Extension WordPress
Vulnérabilités ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
Cette page rassemble les failles publiées pour ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)
7 fiches
ExactMetrics <= 9.1.2 – Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX Action 'exactmetrics_ads_get_token'
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While…
*-9.1.2
9.1.3
23/04/2026
ExactMetrics <= 9.1.2 – Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process
The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation in all versions up to, and including, 9.1.2. This is due to the reports page…
*-9.1.2
9.1.3
22/04/2026
ExactMetrics 7.1.0 – 9.0.2 – Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update
The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in versions 7.1.0 through 9.0.2. This is due to the `update_settings()` function accepting arbitrary plugin setting names without a whitelist of allowed settings.…
7.1.0-9.0.2
9.0.3
10/03/2026
ExactMetrics 8.6.0 – 9.0.2 – Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation
The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2. This is due to the `store_settings()` method in the `ExactMetrics_Onboarding` class accepting a user-supplied `triggered_by` parameter that…
8.0.0-9.0.2
9.0.3
10/03/2026
ExactMetrics <= 8.1.0 – Missing Authorization
The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 8.1.0. This makes…
*-8.1.0
8.2.0
24/01/2025
ExactMetrics <= 7.14.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ExactMetrics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-7.14.1
7.14.2
09/05/2023
ExactMetrics <= 7.12.0 – Authenticated (Contributor+) Cross-Site Scripting
The ExactMetrics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified block options in posts/pages within versions up to, and including, 7.12.0 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level…
*-7.12.0
7.12.1
13/01/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.