Impact
The vulnerability is a missing authorization flaw in the GA4WP WordPress plugin, allowing an attacker to perform privileged operations that should be restricted. The flaw arises from incorrectly configured access control levels, enabling users without proper permissions to execute admin‑level actions. An attacker who can exploit this flaw may modify the plugin’s analytics settings, inject tracking changes, or access sensitive configuration data, undermining the integrity and confidentiality of a site’s analytics data.
Affected Systems
The flaw affects the GA4WP: Google Analytics for WordPress plugin distributed by Passionate Brains. All released versions through and including 2.10.0 are impacted. No other products or versions have been identified.
Risk and Exploitability
The EPSS score is below 1%, indicating a low probability of exploitation, and the issue is not listed in the CISA KEV catalog. The attacker’s path is likely a remote web request to the plugin’s administrative endpoints, assuming the site does not have additional access controls. Although the immediate risk level may be moderate due to the low exploitation likelihood, the potential impact of unauthorized configuration changes is significant. Vulnerability is considered CVE-2026-22517.
OpenCVE Enrichment