The HT Easy GA4 – Google Analytics WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the login() function in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to update the email associated through the plugin with GA4.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16944 | The HT Easy GA4 – Google Analytics WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the login() function in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to update the email associated through the plugin with GA4. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hasthemes
Hasthemes ht Easy Ga4 \(google Analytics 4\) |
|
| CPEs | cpe:2.3:a:hasthemes:ht_easy_ga4_\(google_analytics_4\):*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Hasthemes
Hasthemes ht Easy Ga4 \(google Analytics 4\) |
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-05T15:46:00.410Z
Reserved: 2024-02-01T20:19:22.534Z
Link: CVE-2024-1176
Updated: 2024-08-01T18:33:25.072Z
Status : Awaiting Analysis
Published: 2024-03-13T16:15:17.933
Modified: 2024-11-21T08:49:58.123
Link: CVE-2024-1176
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD