Analytify develops a Google Analytics dashboard plugin that integrates analytics functionality into web applications, placing it in a position to mediate access to sensitive analytics data and user information. The vendor's vulnerability profile centers on a narrow product scope and recurs through access-control and authorization weaknesses—including missing authorization checks, cross-site request forgery, and improper access control—alongside exposure of sensitive system information, reflecting the challenges of securing multi-tenant analytics platforms where authorization boundaries are critical. A meaningful share of the vendor's disclosures reach serious severity; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Analytify over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45830CRITICAL Missing Authorization vulnerability in Analytify.This issue affects Analytify: from n/a through 4.2.3. | Jan 2, 2025 | 9.8 | 28 | NO | NO |
CVE-2022-38137HIGH Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress. | Nov 8, 2022 | 8.8 | 27 | NO | NO |
CVE-2024-35689HIGH Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.2.3. | Jun 8, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-26773HIGH Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a t | Feb 17, 2025 | 8.8 | 23 | NO | NO |
CVE-2023-41695HIGH Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a t | Dec 13, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-1809MEDIUM The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che | May 2, 2024 | 5.4 | 20 | NO | NO |
CVE-2024-53814MEDIUM Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Adnan Analytify wp-analytify.This issue affects Analytify: from n/a through <= 5.4.3. | Dec 9, 2024 | 6.5 | 17 | NO | NO |
CVE-2024-1584MEDIUM The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili | May 2, 2024 | 5.3 | 17 | NO | NO |
CVE-2025-30897MEDIUM Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a t | Mar 27, 2025 | 4.3 | 15 | NO | NO |
CVE-2023-47841MEDIUM Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through 5. | Dec 9, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Analytify.
Media articles that mention a CVE ID that affects a product developed by Analytify — matched by CVE ID, not by vendor name.