PT-2024-17237 · WordPress · Ht Easy Ga4 – Google Analytics Wordpress Plugin

Francesco Carlucci

·

Published

2024-03-13

·

Updated

2024-03-13

·

CVE-2024-1176

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions HT Easy GA4 – Google Analytics WordPress Plugin versions prior to 1.1.6
Description The issue allows unauthorized modification of data due to a missing capability check on the login() function. This makes it possible for unauthenticated attackers to update the email associated with GA4 through the plugin.
Recommendations For versions prior to 1.1.6, update to version 1.1.6 or later to resolve the issue. As a temporary workaround, consider disabling the login() function until a patch is available. Restrict access to the plugin's functionality to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1176

Affected Products

Ht Easy Ga4 – Google Analytics Wordpress Plugin