Extension WordPress

Vulnérabilités MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)

Cette page rassemble les failles publiées pour MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy), leurs plages de versions affectées et les correctifs signalés dans la base locale.

11Vulnérabilités
0Critiques
11Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)

11 fiches

CVE-2026-5371 Élevée · 7,1
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)

MonsterInsights <= 10.1.2 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure And Plugin Integration Reset

The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability checks on the get_ads_access_token() and reset_experience() functions in all…

Versions affectées

*-10.1.2

Correctif

10.1.3

Publication

12/05/2026

CVE-2023-52220 Moyenne · 4,3
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)

Google Analytics by Monster Insights <= 8.21.0 – Missing Authorization

The Google Analytics by Monster Insights plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 8.21.0. This makes it possible for authenticated attackers, with subscriber-level access and…

Versions affectées

*-8.21.0

Correctif

8.22.0

Publication

05/01/2024

CVE-2023-23999 Moyenne · 6,4
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)

Google Analytics by Monster Insights <= 8.14.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Google Analytics by Monster Insights plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.14.0 due to insufficient input sanitization and output escaping on the style attribute. This makes it possible…

Versions affectées

*-8.14.0

Correctif

8.14.1

Publication

10/05/2023

CVE-2023-0081 Moyenne · 6,4
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)

MonsterInsights <= 8.12.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The MonsterInsights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified block options (used in pages and posts) in versions up to, and including, 8.12.0 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-8.12.0

Correctif

8.12.1

Publication

13/01/2023

CVE-2022-3904 Moyenne · 5,4
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)

MonsterInsights <= 8.9.0 – Unauthenticated Stored Cross-Site Scripting via Google Analytics

The MonsterInsights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles and pages in versions up to, and including, 8.9.0 due to insufficient input sanitization and output escaping on those values. This makes it possible…

Versions affectées

*-8.9.0

Correctif

8.9.1

Publication

23/12/2022

Vulnérabilité Moyenne · 6,4
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)

MonsterInsights – Google Analytics Dashboard for WordPress <= 7.1 – Stored Cross-Site Scripting

The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter in versions up to, and including 7.1. This makes it possible for lower-privileged attackers to inject arbitrary…

Versions affectées

*-7.1

Correctif

7.2.0

Publication

18/09/2018

Vulnérabilité Faible · 3,8
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)

MonsterInsights – Google Analytics Dashboard for WordPress <= 5.4.4 – Authenticated Stored Cross-Site Scripting

The MonsterInsights – Google Analytics Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.4 due to insufficient privilege handling. This makes it possible for authenticated attackers to inject arbitrary web…

Versions affectées

*-5.4.4

Correctif

5.4.5

Publication

10/08/2015

Vulnérabilité Élevée · 7,2
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)

MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) <= 5.3.3 – Cross-Site Scripting

The MonsterInsights – Google Analytics Dashboard for WordPress plugin is vulnerable to Cross-Site Scripting via the add_query_arg and remove_query_arg functions in versions up to, and including, 5.3.3. This makes it possible for attackers to inject arbitrary web scripts…

Versions affectées

*-5.3.3

Correctif

5.4

Publication

20/04/2015

Vulnérabilité Élevée · 7,2
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)

MonsterInsights – Google Analytics Dashboard for WordPress <= 5.3.2 – Stored Cross-Site Scripting

The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers…

Versions affectées

*-5.3.2

Correctif

5.3.3

Publication

19/03/2015

Vulnérabilité Moyenne · 5,5
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)

MonsterInsights – Google Analytics Dashboard for WordPress <= 5.3.2 – Authenticated Stored Cross-Site Scripting

The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘manual_ua_code_field’ parameter in versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-5.3.2

Correctif

5.3.3

Publication

06/03/2015

CVE-2014-9174 Faible · 3,5
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)

MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) <= 5.1.2 – Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Manually enter your UA code" (manual_ua_code_field) field in the General…

Versions affectées

*-5.1.2

Correctif

5.1.3

Publication

26/11/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités