Junglewise Threat Intelligence

CVE-2026-8944: IO technologies Plugin for Google Analytics CSRF in ga.php

CVE-2026-8944 · Severity: medium · CVSS 4.3 · Published 2026-06-30

Executive brief

The Plugin for Google Analytics by IO technologies for WordPress is vulnerable to a security flaw that allows attackers to change the website's Google Analytics tracking ID. By tricking a site administrator into clicking a malicious link, an attacker can redirect website traffic statistics to their own account. This can lead to a loss of business intelligence and the exposure of website visitor metrics to unauthorized parties.

Technical details

The Plugin for Google Analytics by IO technologies for WordPress (versions up to 1.1) is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation in the ga.php settings page. An unauthenticated attacker can exploit this by crafting a malicious request to update the 'io-ga-id' option. Successful exploitation requires a site administrator to interact with a malicious link or page while authenticated. This allows the attacker to modify the stored Google Analytics tracking ID, effectively hijacking the site's analytics data stream.

Affected products

  • engagementanalytics Plugin for Google Analytics by IO technologies <= 1.1

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory

References