PT-2024-3161 · WordPress · Analytify

Francesco Carlucci

·

Published

2024-02-16

·

Updated

2025-06-05

·

CVE-2024-1584

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Analytify – Google Analytics Dashboard For WordPress versions up to, and including, 5.2.1
Description: The issue is related to a missing capability check on the wpa check authentication function, which allows unauthorized modification of data. This makes it possible for unauthenticated attackers to modify the site's Google Analytics tracking ID. The vulnerability can be exploited by a remote attacker to change the site's Google Analytics tracking ID due to insufficient authorization procedure.
Recommendations: For versions up to, and including, 5.2.1, update to a version that includes a fix for the missing capability check on the wpa check authentication function. As a temporary workaround, consider restricting access to the wpa check authentication function until a patch is available.

Fix

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-03374
CVE-2024-1584

Affected Products

Analytify