Vulnerabilities
Summary — last 7 days
New vulnerabilities2,765▼ 50 vs. last week
Critical / high1,432▲ 200 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)95▼ 405 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (5.3) | 0.54% | — | Daan Complete Analytics Optimization Suite | 1/11/2024 | 6/17/2026 | The CAOS | Host Google Analytics Locally plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_settings' function in versions up to, and including, 4.7.14. This makes it possible for unauthenticated attackers to update plugin settings. | |
| Modified | Medium (4.9) | 1.0% | — | Daan Complete Analytics Optimization Suite | 1/3/2022 | 6/17/2026 | The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin |