• About Us
  • Contributors
  • Guides
  • Speaking Engagements
  • Write for The SEM Post
  • Submit a tip or contact us!
  • Newsletters

The SEM Post

Latest News About SEO, SEM, PPC & Search Engines

  • Google
  • SEO
  • Mobile
  • Local
  • Bing
  • Pay Per Click
  • Facebook
  • Twitter
  • State of the Industry
You are here: Home / Google / Analytics / Exploit Discovered in Google Analytics by Yoast Wordpress Plugin

Exploit Discovered in Google Analytics by Yoast WordPress Plugin

March 23, 2015 at 4:33 am PST By Jennifer Slegg

  • Facebook
  • Twitter
  • Google+
  • Pinterest
  • LinkedIn
  • Email
  • WhatsApp
  • Evernote
  • SMS

analyticsyoastYet another major vulnerability has been discovered with a WordPress plugin popular with SEOs and webmasters.  And it is another Yoast plugin that is affected, this time the very popular Google Analytics by Yoast plugin.  This particular exploit used XSS in order to run malicious code.

Those who use this plugin by Yoast need to ensure they are running the latest version – 5.3.3, which was released on March 19, 2015, in order to be protected.  If you have your WordPress auto-update plugins, you should be running the current version, but it is always good practice to ensure the update processed correctly.  If you update plugins manually, you should update the plugin immediately.

5.3.3

Release Date: March 19th, 2015

  • Several security fixes:
    1. Fix minor XSS issue where admins could XSS each other through an unescaped manual UA field.
    2. Fix stored XSS issue where changing a property’s name in Google Analytics to contain malicious JS would allow execution of that JS in the admin as the profile name was not escaped properly.
    3. Fix un-authenticated change of the GA profile list, allowing the previous XSS to become a slightly bigger issue. Issues 2 and 3 combined lead to a DREAD score of 5.

Big thanks to Jouko Pynnönen for responsibly disclosing security issues #2 and #3.

The popular plugin, which has over one million active installs, also has a premium paid version of the plugin along with the free one.  Both versions are affected by this exploit.

As with the other recent Yoast plugin to be affected by an exploit – SEO by Yoast – they fixed the vulnerability within one day of it being responsibly disclosed to Yoast, meaning those who use Yoast plugins were in little danger as long as they deploy WordPress plugin updates immediately.

No known cases of the exploit being used for nefarious reason had been reported by the time the fix went out, but as always, when a vulnerability is disclosed, many try to take advantage of those sites running outdated plugins that have not been recently updated.

There have been a rash of plugins popular with SEOs that have had vulnerabilities discovered recently.  In addition to the two Yoast plugins, Shareaholic, RevSlider and Fancybox-for-Wordpress have all recently fixed exploits.

Should webmasters be reluctant to use these plugins?  When it comes to any popular plugin, there are always those trying to find vulnerabilities to exploit.  Popular ones are often the targets because many are installed on abandoned or neglected blogs which tend to not get plugins updated as regularly.  And often the larger plugins have a team behind them that can turnaround immediate patches, which we have seen in the Yoast cases.  Instead, warning signs of a potentially bad plugin are plugins that haven’t been updated in quite some time and ones that don’t answer or resolve support threads over several months.

Bottom line, with all the WordPress vulnerabilities lately, you should not only take the time to update Google Analytics by Yoast, but update all the plugins you currently run.

  • Facebook
  • Twitter
  • Google+
  • Pinterest
  • LinkedIn
  • Email
  • WhatsApp
  • Evernote
  • SMS
The following two tabs change content below.
  • Bio
  • Latest Posts
My Twitter profileMy Facebook profileMy Google+ profileMy LinkedIn profile

Jennifer Slegg

Founder & Editor at The SEM Post
Jennifer Slegg is a longtime speaker and expert in search engine marketing, working in the industry for almost 20 years. When she isn't sitting at her desk writing and working, she can be found grabbing a latte at her local Starbucks or planning her next trip to Disneyland. She regularly speaks at Pubcon, SMX, State of Search, Brighton SEO and more, and has been presenting at conferences for over a decade.
My Twitter profileMy Facebook profileMy Google+ profileMy LinkedIn profile

Latest posts by Jennifer Slegg (see all)

  • 2022 Update for Google Quality Rater Guidelines – Big YMYL Updates - August 1, 2022
  • Google Quality Rater Guidelines: The Low Quality 2021 Update - October 19, 2021
  • Rethinking Affiliate Sites With Google’s Product Review Update - April 23, 2021
  • New Google Quality Rater Guidelines, Update Adds Emphasis on Needs Met - October 16, 2020
  • Google Updates Experiment Statistics for Quality Raters - October 6, 2020

Filed Under: Analytics, SEO

Sign up for our newsletter


Trackbacks

  1. WP Super Cache Latest Plugin With Major XXS Exploit, Requires Immediate Update - The SEM Post says:
    April 8, 2015 at 3:18 am

    […] in a string of plugins popular with the SEO community to have a discovered exploit patched.  Google Analytics by Yoast, WordPress SEO by Yoast, Shareaholic, RevSlider and Fancybox-for-Wordpress have all recently fixed […]

Founder & Editor

Jennifer Slegg (2052)

Sign up for our daily news recap & weekly newsletter.


Follow us online

  • Facebook
  • Google+
  • Linkedin
  • Pinterest
  • Twitter

Latest News

2022 Update for Google Quality Rater Guidelines – Big YMYL Updates

We finally have the first Google Quality Rater Guidelines update of 2022, and like usual, it is … [Read More...]

Recent Posts

  • 2022 Update for Google Quality Rater Guidelines – Big YMYL Updates
  • Google Quality Rater Guidelines: The Low Quality 2021 Update
  • Rethinking Affiliate Sites With Google’s Product Review Update
  • New Google Quality Rater Guidelines, Update Adds Emphasis on Needs Met
  • Google Updates Experiment Statistics for Quality Raters
  • Analyzing “How Google Search Works” Changes from Google
  • Google Quality Rater Guidelines Update: New Introduction, Rater Bias & Political Affiliations
  • Google Updates Quality Rater Guidelines: Reputation for News Sites; Video Content Updates; Quality for Information Sites
  • Google Makes Major Changes to NoFollow, Adds Sponsored & UGC Tags
  • Google Updates Quality Rater Guidelines Targeting E-A-T, Page Quality & Interstitials

Categories

  • Affiliate Marketing
  • Amazon
  • Apple
  • Bing
  • Branding
  • Browsers
  • Chrome
  • Content Marketing
  • Design
  • Domains
  • DuckDuckGo
  • Email
  • Facebook
  • Firefox
  • Foursquare
  • Google
    • Analytics
    • Google RankBrain
    • Quality Rater's Guidelines
  • History of Search
  • Industry Spotlight
  • Instagram
  • Internet Explorer
  • Links
  • Local
  • Mobile
  • Native Advertising
  • Other Search Engines
  • Pay Per Click
  • Pinterest
  • Publishers
  • Security
  • SEO
  • Snapchat
  • Social Media
  • State of the Industry
  • The SEM Post
  • Tools
  • Twitter
  • Uncategorized
  • User Experience
  • Video Marketing
  • Week in Review
  • Whitepapers
  • Wordpress
  • Yahoo
  • Yelp
  • YouTube
December 2025
MTWTFSS
« Aug  
1234567
891011121314
15161718192021
22232425262728
293031 

Meta

  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org

Copyright © 2025 · News Pro Theme On Genesis Framework · WordPress · Log in