CVE-2014-9174: XSS
Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Manually enter your UA code" (manualuacodefield) field in the General Settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9174?
The severity of CVE-2014-9174 is considered to be medium due to its cross-site scripting (XSS) implications.
How do I fix CVE-2014-9174?
To fix CVE-2014-9174, update the Google Analytics by Yoast plugin to version 5.1.3 or later.
Who is affected by CVE-2014-9174?
Users of the Google Analytics by Yoast plugin for WordPress versions 5.1.2 and earlier are affected by CVE-2014-9174.
What type of vulnerability is CVE-2014-9174?
CVE-2014-9174 is a cross-site scripting (XSS) vulnerability.
Can CVE-2014-9174 be exploited remotely?
Yes, CVE-2014-9174 can be exploited remotely by injecting arbitrary web scripts or HTML.