The HT Easy GA4 – Google Analytics WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the login() function in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to update the email associated through the plugin with GA4.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16944 | The HT Easy GA4 – Google Analytics WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the login() function in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to update the email associated through the plugin with GA4. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 08 Apr 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hasthemes ht Easy Ga4
|
|
| CPEs | cpe:2.3:a:hasthemes:ht_easy_ga4:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Hasthemes ht Easy Ga4
|
Wed, 08 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | HT Easy GA4 – Google Analytics WordPress Plugin <= 1.1.5 - Missing Authorization to Unauthenticated GA4 Email Update | |
| Weaknesses | CWE-862 | |
| References |
|
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hasthemes
Hasthemes ht Easy Ga4 \(google Analytics 4\) |
|
| CPEs | cpe:2.3:a:hasthemes:ht_easy_ga4_\(google_analytics_4\):*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Hasthemes
Hasthemes ht Easy Ga4 \(google Analytics 4\) |
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:36:08.059Z
Reserved: 2024-02-01T20:19:22.534Z
Link: CVE-2024-1176
Updated: 2024-08-01T18:33:25.072Z
Status : Modified
Published: 2024-03-13T16:15:17.933
Modified: 2026-04-08T17:18:16.710
Link: CVE-2024-1176
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD