CVE-2024-13362
GA4WP – Analytics Dashboard for the Website
Minimum safe version
2.10.0
Update to 2.10.0 or later to address 6 fixable vulnerabilities
Latest available2.10.0 ✓⚠ 2 vulnerabilities have no fix
Medium 6.1
2026-05-01< 2.10.0
Medium 6.5 Unfixed
2026-02-20≤ 2.10.0
WordPress GA4WP: Google Analytics for WordPress plugin <= 2.10.0 - Broken Access Control vulnerability
Medium 5.4 Unfixed
2026-01-08≤ 2.10.0
WordPress GA4WP: Google Analytics for WordPress plugin <= 2.10.0 - Broken Access Control vulnerability
Medium 6.3
2024-10-16< 1.3
Freemius SDK <= 2.4.2 - Missing Authorization Checks
N/A
2023-07-18< 2.2.0
WordPress GA4WP: Google Analytics for WordPress Plugin < 2.2.0 is vulnerable to Cross Site Scripting (XSS)
N/A
2022-03-04< 1.3
Freemius SDK <= 2.4.2 - Missing Authorization Checks
N/A
2022-02-28< 1.3
WordPress GA4WP: Google Analytics for WordPress plugin < 1.3 - Sensitive Information Disclosure vulnerability
N/A
2022-02-28< 1.3
WordPress GA4WP: Google Analytics for WordPress plugin < 1.3 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability