Description
Cross-Site Request Forgery (CSRF) vulnerability in hoyce Universal Analytics Injector universal-analytics-injector allows Stored XSS.This issue affects Universal Analytics Injector: from n/a through <= 1.0.3.
Published: 2025-01-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a Cross‑Site Request Forgery that allows an attacker to persist arbitrary JavaScript through the Universal Analytics Injector plugin. The lack of anti‑CSRF protection, identified as CWE‑352, results in stored cross‑site scripting. Once malicious code is saved, any authenticated visitor who subsequently loads the affected page will execute the script, potentially hijacking sessions, stealing cookies, or modifying page content. The flaw resides in the plugin’s administrative interface, meaning that attacker control requires an authenticated user to submit a crafted request.

Affected Systems

The issue affects WordPress sites that use the hoyce Universal Analytics Injector plugin version 1.0.3 or earlier. No other plugins or versions are listed, so only installations of this plugin at those versions are vulnerable.

Risk and Exploitability

The assigned CVSS base score of 7.1 reflects a high severity. The EPSS score of less than 1% indicates that the vulnerability has not yet attracted widespread exploitation and it is not present in the CISA KEV catalog. Attackers would need to construct a CSRF request, typically from a malicious site or script, targeting an authenticated user with access to the plugin’s settings. Successful exploitation results in the stored script being served to all subsequent visitors, creating a persistent threat that is hard to mitigate without a patch.

Generated by OpenCVE AI on May 2, 2026 at 09:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Universal Analytics Injector to version 1.0.4 or newer to eliminate the CSRF flaw.
  • If an upgrade is not immediately possible, remove or deactivate the plugin so the vulnerable code path is no longer executed.
  • Deploy a site‑wide content security policy that disallows inline scripts or uses nonces/hashes to reduce the impact of any stored XSS.

Generated by OpenCVE AI on May 2, 2026 at 09:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3204 Cross-Site Request Forgery (CSRF) vulnerability in Niklas Olsson Universal Analytics Injector allows Stored XSS.This issue affects Universal Analytics Injector: from n/a through 1.0.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Niklas Olsson Universal Analytics Injector allows Stored XSS.This issue affects Universal Analytics Injector: from n/a through 1.0.3. Cross-Site Request Forgery (CSRF) vulnerability in hoyce Universal Analytics Injector universal-analytics-injector allows Stored XSS.This issue affects Universal Analytics Injector: from n/a through <= 1.0.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Niklas Olsson Universal Analytics Injector allows Stored XSS.This issue affects Universal Analytics Injector: from n/a through 1.0.3.
Title WordPress Universal Analytics Injector plugin <= 1.0.3 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:10.288Z

Reserved: 2025-01-16T11:25:20.560Z

Link: CVE-2025-23483

cve-icon Vulnrichment

Updated: 2025-01-17T17:22:55.027Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T20:15:37.133

Modified: 2026-06-17T08:54:43.923

Link: CVE-2025-23483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T10:00:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)