WPIntell

Source evidence

Plugin security vulnerability

Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) · support · 2024-08-18T12:55:00+00:00

neutralsentiment
highseverity
0.58relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 31 rows with source links

16.1% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

26 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
globalexposures resolved
There is a cross-scripting vulnerability with the dashboard widget. It was reported back in May. CVE-2024-35689 It has apparently not been patched yet. The page I need help with: [ log in to see the link] Hi @mom2nine , The vulnerability you reported is already fixed in version 5.2.4, which was updated on 08 Jun 2024 . Please check the reference in CVE-2024-35689: https://patchstack.com/database/vulnerability/wp-analytify/wordpress-analytify-plugin-5-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve . Kindly, update the Analytify plugin to the latest version 5.3.1 if you are still using the old one. Thank you!

Comments

1 shown
Emma 2024-08-19T07:44:00+00:00

Hi @mom2nine , The vulnerability you reported is already fixed in version 5.2.4, which was updated on 08 Jun 2024 . Please check the reference in CVE-2024-35689: https://patchstack.com/database/vulnerability/wp-analytify/wordpress-analytify-plugin-5-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve . Kindly, update the Analytify plugin to the latest version 5.3.1 if you are still using the old one. Thank you!