Impact
The vulnerability is a missing authorization check in the Advanced Google Universal Analytics plugin for WordPress. It stems from incorrectly configured access control levels, allowing an attacker to read sensitive data that should be protected. The weakness falls under CWE-862 (Missing Authorization). An attacker leveraging this flaw could obtain private analytics data and other plugin configuration details, compromising confidentiality and potentially facilitating further attacks. The impact is data exposure rather than code execution.
Affected Systems
The affected vendor is stefanoai, producing the Advanced Google Universal Analytics plugin. All versions from an unspecified prior release through version 1.0.3 are impacted. Site owners running the plugin under any user role should consider this vulnerability active until the plugin is updated.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is below 1%, suggesting exploitation probability is very low at this time. The plugin is not listed in CISA KEV. Attackers likely need to send an HTTP request to a plugin endpoint that does not enforce proper role checks, which is generally feasible from any authenticated or even unauthenticated user depending on plugin configuration. Because the flaw is a broken access control, the attack vector is probably remote web access.
OpenCVE Enrichment
EUVD