Known vulnerabilities, PHP compatibility and safer alternatives for the Wp Analytify WordPress plugin — checked against WP Clinic's local security database.
What this plugin does
Maintenance status
Known vulnerabilities
11 known CVEs on file for Wp Analytify.
Reported between 2022 and 2025.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-30897
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 6.0.0 |
Missing Authorization |
Medium
4.3
|
< 6.0.0
|
6.0.0 |
2025-03-27 |
—
|
|
CVE-2025-26773
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.5.1 |
Missing Authorization |
Medium
4.3
|
< 5.5.1
|
5.5.1 |
2025-02-14 |
—
|
|
CVE-2024-53814
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.5.0 |
Exposure of Sensitive System Information to an Unauthorized Control Sphere |
Medium
6.5
|
< 5.5.0
|
5.5.0 |
2024-12-02 |
—
|
|
CVE-2024-43265
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.4.0 |
Cross-Site Request Forgery (CSRF) |
Low
3.5
|
< 5.4.0
|
5.4.0 |
2024-08-12 |
—
|
|
CVE-2024-35689
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 5.2.4
|
5.2.4 |
2024-06-06 |
—
|
|
CVE-2024-1809
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 |
Exposure of Sensitive System Information to an Unauthorized Control Sphere |
Medium
5.4
|
< 5.2.4
|
5.2.4 |
2024-04-29 |
—
|
|
CVE-2024-1584
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 |
Improper Access Control |
Medium
5.3
|
< 5.2.4
|
5.2.4 |
2024-04-26 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.0 |
— |
Unknown
|
< 5.2.0
|
5.2.0 |
2023-11-20 |
—
|
CVE-2025-30897
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rated() function in all versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set the rated option to true.
Source:
Wordfence
CVE-2025-26773
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Source:
Wordfence
CVE-2024-53814
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.4.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Source:
Wordfence
CVE-2024-43265
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3.1. This is due to missing or incorrect nonce validation on the optout_yes() function. This makes it possible for unauthenticated attackers to opt out of tracking via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
CVE-2024-35689
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.3. This is due to missing or incorrect nonce validation on the wpa_check_authentication() function. This makes it possible for unauthenticated attackers to update the Google Analytics tracking code via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
CVE-2024-1809
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain certain sensitive information related to plugin settings.
Source:
CVE.org
CVE-2024-1584
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1. This makes it possible for unauthenticated attackers to modify the site's Google Analytics tracking ID.
Source:
CVE.org
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.0
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on the send_analytics_email function. This makes it possible for unauthenticated attackers to send a feedback email usually sent on uninstall with admin consent via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
+ 10 more known vulnerabilities
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-47841
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.0 |
Missing Authorization |
Medium
4.3
|
< 5.2.0
|
5.2.0 |
2023-11-20 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.1.1 |
— |
Unknown
|
< 5.1.1
|
5.1.1 |
2023-09-05 |
—
|
|
CVE-2023-41695
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.1.1 |
Missing Authorization |
Low
3.5
|
< 5.1.1
|
5.1.1 |
2023-09-05 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0 |
— |
Unknown
|
< 4.3.0
|
4.3.0 |
2023-01-03 |
—
|
|
CVE-2022-45830
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0 |
Missing Authorization |
Medium
6.5
|
< 4.3.0
|
4.3.0 |
2022-12-29 |
—
|
|
CVE-2022-38137
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.3 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 4.2.3
|
4.2.3 |
2022-09-29 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.3 |
— |
Unknown
|
< 4.2.3
|
4.2.3 |
2022-08-22 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 |
— |
Unknown
|
< 4.2.1
|
4.2.1 |
2022-06-20 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 |
— |
Unknown
|
< 4.2.1
|
4.2.1 |
2022-06-20 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 |
— |
Unknown
|
< 4.2.1
|
4.2.1 |
— |
—
|
CVE-2023-47841
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on the send_analytics_email function. This makes it possible for unauthenticated attackers to send a feedback email usually sent on uninstall with admin consent via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
WPScan
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.1.1
The Analytify Dashboard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the optin_yes() function in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber-level and above access, to optin the the plugin's tracking.
Source:
Wordfence
CVE-2023-41695
Update the WordPress Analytify plugin to the latest available version (at least 5.1.1).
Abdi Pranata discovered and reported this Broken Access Control vulnerability in WordPress Analytify Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 5.1.1.
Source:
Patchstack
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0
The Analytify plugin for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 4.2.3. This is due to missing nonce validation and a lack of capability checking on the logout() function. This makes it possible for unauthenticated attackers to invoke this function and log out an associated Google Analytics account either themself or via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
CVE-2022-45830
Update the WordPress Analytify plugin to the latest available version (at least 4.3.0).
Tien Nguyen Anh discovered and reported this Privilege Escalation vulnerability in WordPress Analytify Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website. This vulnerability has been fixed in version 4.3.0.
Source:
Patchstack
CVE-2022-38137
The Analytify – Google Analytics Dashboard For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.2. This is due to missing or incorrect nonce validation on the analytify_delete_cache action. This makes it possible for unauthenticated attackers to delete the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.3
The Analytify plugin for WordPress is vulnerable to authorization bypass due to a missing capability and nonce checks on the analytify_delete_cache function in versions up to, and including, 4.2.2 . This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the cache of the plugin and also allows unauthenticated attackers to delete the plugin cache via forged request, granted they can trick a subscriber or higher into clicking on a link. Version 4.2.3 adds a nonce check to the function, which addressed the Cross-Site Request Forgery Vulnerability and makes exploitation impractical for lower-level accounts.
Source:
Wordfence
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Analytify plugin (versions <= 4.2.0).
Update the WordPress Analytify plugin to the latest available version (at least 4.2.1).
Source:
Patchstack
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1
The Analytify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.2.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Source:
Wordfence
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1
The plugin does not escape the current URL before outputting it back in a 404 page when the 404 tracking feature is enabled, leading to Reflected Cross-Site Scripting
Source:
WPScan
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.