CVE-2024-1809: Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) <= 5.2.3 - Missing Authorization
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain certain sensitive information related to plugin settings.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1809?
CVE-2024-1809 has a high severity rating due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2024-1809?
To fix CVE-2024-1809, update the Analytify plugin to version 5.2.4 or later to address the missing capability check.
What causes CVE-2024-1809?
CVE-2024-1809 is caused by a missing capability check on AJAX functions combined with nonce leakage.
Which versions of Analytify are affected by CVE-2024-1809?
All versions of the Analytify plugin up to and including version 5.2.3 are affected by CVE-2024-1809.
What should I do if I cannot update Analytify due to compatibility issues?
If you cannot update Analytify, consider disabling the plugin until you can ensure a secure version is installed.