WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Wp Analytify safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Wp Analytify WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: wp-analytify

Maintenance status

Known vulnerabilities

11 known CVEs on file for Wp Analytify. Reported between 2022 and 2025.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-30897 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 6.0.0 Missing Authorization Medium 4.3 < 6.0.0 6.0.0 2025-03-27
CVE-2025-26773 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.5.1 Missing Authorization Medium 4.3 < 5.5.1 5.5.1 2025-02-14
CVE-2024-53814 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.5.0 Exposure of Sensitive System Information to an Unauthorized Control Sphere Medium 6.5 < 5.5.0 5.5.0 2024-12-02
CVE-2024-43265 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.4.0 Cross-Site Request Forgery (CSRF) Low 3.5 < 5.4.0 5.4.0 2024-08-12
CVE-2024-35689 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 Cross-Site Request Forgery (CSRF) High 8.8 < 5.2.4 5.2.4 2024-06-06
CVE-2024-1809 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 Exposure of Sensitive System Information to an Unauthorized Control Sphere Medium 5.4 < 5.2.4 5.2.4 2024-04-29
CVE-2024-1584 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 Improper Access Control Medium 5.3 < 5.2.4 5.2.4 2024-04-26
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.0 Unknown < 5.2.0 5.2.0 2023-11-20

CVE-2025-30897

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rated() function in all versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set the rated option to true.

Source: Wordfence

CVE-2025-26773

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

Source: Wordfence

CVE-2024-53814

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.4.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

Source: Wordfence

CVE-2024-43265

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3.1. This is due to missing or incorrect nonce validation on the optout_yes() function. This makes it possible for unauthenticated attackers to opt out of tracking via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

CVE-2024-35689

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.3. This is due to missing or incorrect nonce validation on the wpa_check_authentication() function. This makes it possible for unauthenticated attackers to update the Google Analytics tracking code via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

CVE-2024-1809

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain certain sensitive information related to plugin settings.

Source: CVE.org

CVE-2024-1584

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1. This makes it possible for unauthenticated attackers to modify the site's Google Analytics tracking ID.

Source: CVE.org

Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.0

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on the send_analytics_email function. This makes it possible for unauthenticated attackers to send a feedback email usually sent on uninstall with admin consent via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

+ 10 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-47841 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.0 Missing Authorization Medium 4.3 < 5.2.0 5.2.0 2023-11-20
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.1.1 Unknown < 5.1.1 5.1.1 2023-09-05
CVE-2023-41695 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.1.1 Missing Authorization Low 3.5 < 5.1.1 5.1.1 2023-09-05
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0 Unknown < 4.3.0 4.3.0 2023-01-03
CVE-2022-45830 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0 Missing Authorization Medium 6.5 < 4.3.0 4.3.0 2022-12-29
CVE-2022-38137 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.3 Cross-Site Request Forgery (CSRF) Medium 4.3 < 4.2.3 4.2.3 2022-09-29
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.3 Unknown < 4.2.3 4.2.3 2022-08-22
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 Unknown < 4.2.1 4.2.1 2022-06-20
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 Unknown < 4.2.1 4.2.1 2022-06-20
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 Unknown < 4.2.1 4.2.1

CVE-2023-47841

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on the send_analytics_email function. This makes it possible for unauthenticated attackers to send a feedback email usually sent on uninstall with admin consent via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: WPScan

Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.1.1

The Analytify Dashboard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the optin_yes() function in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber-level and above access, to optin the the plugin's tracking.

Source: Wordfence

CVE-2023-41695

Update the WordPress Analytify plugin to the latest available version (at least 5.1.1). Abdi Pranata discovered and reported this Broken Access Control vulnerability in WordPress Analytify Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 5.1.1.

Source: Patchstack

Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0

The Analytify plugin for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 4.2.3. This is due to missing nonce validation and a lack of capability checking on the logout() function. This makes it possible for unauthenticated attackers to invoke this function and log out an associated Google Analytics account either themself or via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

CVE-2022-45830

Update the WordPress Analytify plugin to the latest available version (at least 4.3.0). Tien Nguyen Anh discovered and reported this Privilege Escalation vulnerability in WordPress Analytify Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website. This vulnerability has been fixed in version 4.3.0.

Source: Patchstack

CVE-2022-38137

The Analytify – Google Analytics Dashboard For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.2. This is due to missing or incorrect nonce validation on the analytify_delete_cache action. This makes it possible for unauthenticated attackers to delete the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.3

The Analytify plugin for WordPress is vulnerable to authorization bypass due to a missing capability and nonce checks on the analytify_delete_cache function in versions up to, and including, 4.2.2 . This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the cache of the plugin and also allows unauthenticated attackers to delete the plugin cache via forged request, granted they can trick a subscriber or higher into clicking on a link. Version 4.2.3 adds a nonce check to the function, which addressed the Cross-Site Request Forgery Vulnerability and makes exploitation impractical for lower-level accounts.

Source: Wordfence

Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Analytify plugin (versions <= 4.2.0). Update the WordPress Analytify plugin to the latest available version (at least 4.2.1).

Source: Patchstack

Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1

The Analytify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.2.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Source: Wordfence

Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1

The plugin does not escape the current URL before outputting it back in a 404 page when the 404 tracking feature is enabled, leading to Reflected Cross-Site Scripting

Source: WPScan

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.