The plugin does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
Plugin needs to be connected to Google Analytics account. https://example.com/wp-admin/admin.php?page=googleanalytics&ga_action=%22%3E%3Cimg+src%3Dx+onerror%3Dalert%28document.domain%29%3E
renniepak
renniepak
Yes
2021-08-02 (about 1 years ago)
2021-08-02 (about 1 years ago)
2022-02-24 (about 1 years ago)