The HT Easy GA4 – Google Analytics WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the login() function in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to update the email associated through the plugin with GA4.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hasthemes
Hasthemes ht Easy Ga4 \(google Analytics 4\) |
|
| CPEs | cpe:2.3:a:hasthemes:ht_easy_ga4_\(google_analytics_4\):*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Hasthemes
Hasthemes ht Easy Ga4 \(google Analytics 4\) |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-03-13T15:26:33.603Z
Updated: 2024-08-05T15:46:00.410Z
Reserved: 2024-02-01T20:19:22.534Z
Link: CVE-2024-1176
Updated: 2024-08-01T18:33:25.072Z
Status : Awaiting Analysis
Published: 2024-03-13T16:15:17.933
Modified: 2024-11-21T08:49:58.123
Link: CVE-2024-1176
No data.
ReportizFlow