PT-2026-2194 · Passionate Brains · Ga4Wp: Google Analytics For Wordpress+1

Legion Hunter

·

Published

2026-01-08

·

Updated

2026-01-09

·

CVE-2026-22517

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions GA4WP: Google Analytics for WordPress versions through 2.10.0
Description A missing authorization issue exists in Passionate Brains GA4WP: Google Analytics for WordPress, allowing exploitation of incorrectly configured access control security levels.
Recommendations Update GA4WP: Google Analytics for WordPress to a version later than 2.10.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-22517

Affected Products

Ga4Wp: Google Analytics For Wordpress
Google Analytics For Wordpress