Input validation vulnerability in Cookieless Backend Server Tracking for Google Analytics – WordPress Plugin 1.2.1

The Google Analytics – WordPress Plugin for WordPress, used to track website activity, is vulnerable to Cross-Site Scripting (XSS) in versions before 1.2.1. This means attackers can inject malicious web scripts into the plugin that will run in the browser of anyone who visits the website. The vulnerability is caused by a lack of protection in the ‘attr’ parameter, which allows the scripts to get through.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.