Input validation vulnerability in GA Google Analytics – Connect Google Analytics to WordPress 20210211

The GA Google Analytics plugin for WordPress is vulnerable to a type of malicious attack called Stored Cross-Site Scripting. This attack is possible in versions up to and including 20220517. Attackers who have administrative privileges can inject web scripts into pages which will be executed every time someone visits the page. This vulnerability only affects multi-site installations and installations where a specific security feature called “unfiltered_html” is disabled.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.