Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Afnaan

#54697of 56,337
4.3Total CVSS
Vulnerabilities · 1
PT-2026-53812
4.3
2026-06-30
Io Technologies · Plugin For Google Analytics · CVE-2026-8944
**Name of the Vulnerable Software and Affected Versions** Plugin for Google Analytics by IO technologies versions prior to 1.2 **Description** Cross-Site Request Forgery occurs on the Google Analytics settings page 'ga.php' due to missing or incorrect nonce validation. A nonce is a unique token used to prevent the replay of a request. This allows unauthenticated attackers to update the stored Google Analytics tracking ID option `io-ga-id` by tricking a site administrator into clicking a malicious link. **Recommendations** Update the plugin to a version newer than 1.1.