ZeroHour

CVE-2024-1809

CVSS 3.1
5.4 medium
EPSS
<1%p21
Published
()
Modified
Description

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain certain sensitive information related to plugin settings.

Vendors
analytify
Products
analytify - google analytics dashboard
Ecosystems
WordPress
Weakness
CWE-497, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.