CVE-2020-20626
An authenticated stored Cross-Site Scripting (XSS) vulnerability within the "Google Analytics – by Lara" WordPress plugin was found to be exploited in the wild by security vendor NinTechNet.
Source: WPScan
PLUGIN SECURITY
Full width Google Analytics dashboard widget for Wordpress admin interface, which also inserts latest Google Analytics (GA4) tracking code to your pag …
lara-google-analyticsanalyticsgoogle analyticsgoogle analytics dashboardgoogle analytics plugingoogle analytics widget
1 known CVE on file for Lara's Google Analytics (GA4). Reported between 2019 and 2019.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2020-20626 | Lara's Google Analytics (GA4) [lara-google-analytics] < 2.0.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.0.5 | 2.0.5 | 2019-10-14 | — |
An authenticated stored Cross-Site Scripting (XSS) vulnerability within the "Google Analytics – by Lara" WordPress plugin was found to be exploited in the wild by security vendor NinTechNet.
Source: WPScan
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.