Extension WordPress
Vulnérabilités MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
Cette page rassemble les failles publiées pour MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
11 fiches
MonsterInsights <= 10.1.2 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure And Plugin Integration Reset
The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability checks on the get_ads_access_token() and reset_experience() functions in all…
*-10.1.2
10.1.3
12/05/2026
Google Analytics by Monster Insights <= 8.21.0 – Missing Authorization
The Google Analytics by Monster Insights plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 8.21.0. This makes it possible for authenticated attackers, with subscriber-level access and…
*-8.21.0
8.22.0
05/01/2024
Google Analytics by Monster Insights <= 8.14.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Google Analytics by Monster Insights plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.14.0 due to insufficient input sanitization and output escaping on the style attribute. This makes it possible…
*-8.14.0
8.14.1
10/05/2023
MonsterInsights <= 8.12.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The MonsterInsights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified block options (used in pages and posts) in versions up to, and including, 8.12.0 due to insufficient input sanitization and output escaping. This makes it…
*-8.12.0
8.12.1
13/01/2023
MonsterInsights <= 8.9.0 – Unauthenticated Stored Cross-Site Scripting via Google Analytics
The MonsterInsights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles and pages in versions up to, and including, 8.9.0 due to insufficient input sanitization and output escaping on those values. This makes it possible…
*-8.9.0
8.9.1
23/12/2022
MonsterInsights – Google Analytics Dashboard for WordPress <= 7.1 – Stored Cross-Site Scripting
The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter in versions up to, and including 7.1. This makes it possible for lower-privileged attackers to inject arbitrary…
*-7.1
7.2.0
18/09/2018
MonsterInsights – Google Analytics Dashboard for WordPress <= 5.4.4 – Authenticated Stored Cross-Site Scripting
The MonsterInsights – Google Analytics Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.4 due to insufficient privilege handling. This makes it possible for authenticated attackers to inject arbitrary web…
*-5.4.4
5.4.5
10/08/2015
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) <= 5.3.3 – Cross-Site Scripting
The MonsterInsights – Google Analytics Dashboard for WordPress plugin is vulnerable to Cross-Site Scripting via the add_query_arg and remove_query_arg functions in versions up to, and including, 5.3.3. This makes it possible for attackers to inject arbitrary web scripts…
*-5.3.3
5.4
20/04/2015
MonsterInsights – Google Analytics Dashboard for WordPress <= 5.3.2 – Stored Cross-Site Scripting
The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers…
*-5.3.2
5.3.3
19/03/2015
MonsterInsights – Google Analytics Dashboard for WordPress <= 5.3.2 – Authenticated Stored Cross-Site Scripting
The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘manual_ua_code_field’ parameter in versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping. This makes…
*-5.3.2
5.3.3
06/03/2015
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) <= 5.1.2 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Manually enter your UA code" (manual_ua_code_field) field in the General…
*-5.1.2
5.1.3
26/11/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.