Beta

Report

HT Easy GA4 ( Google Analytics 4 ) <= 1.1.9 is vulnerable to Missing Authorization to Unauthenticated GA4 Email Update vulnerability

Unauthenticated
Published
2024-03-10

The HT Easy GA4 – Google Analytics WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the login() function in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to update the email associated through the plugin with GA4.

CVSS

Score:5.3

Severity:Medium

Version: 1.1.9

There is a patch available in v1.2.0 and we strongly recommend you update to this version as soon as possible.