S4E just found a high-severity finding from cve-2025-58360 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2024-0250 Scanner

CVE-2024-0250 Scanner - Open Redirect vulnerability in Analytics Insights for Google Analytics

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-0250
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Analytics Insights for Google Analytics 4 (AIWP)
AFFECTED< 6.3SAFE ✓≥ 6.3
Updated Aug 22, 2026View on NVD →
Detail

Analytics Insights for Google Analytics 4 is a plugin widely used by WordPress site administrators to integrate their websites with Google Analytics. This software allows users to track and analyze their website traffic, gather insights into user behavior, and make informed decisions based on data. It is popular among small to medium-sized businesses seeking to leverage Google Analytics without extensive technical knowledge. The plugin simplifies the process of connecting a WordPress site to Google's analytics platform, making it accessible to a broader audience. Analytics Insights serves website owners aiming to optimize content strategy and improve user engagement through data analytics. The tool is an essential part of digital marketing strategies, enhancing the ability to monitor traffic and conversion metrics accurately.

An Open Redirect is a vulnerability that enables attackers to redirect users from a trusted website to a potentially malicious site. This happens when the redirect URL is not adequately validated in the application, allowing attackers to create misleading links that appear legitimate. The vulnerability in question affects the oauth2callback.php file, making it possible to alter the redirection destination. If exploited, users can be tricked into visiting harmful sites by simply clicking on a manipulated link. The impact of such vulnerabilities can include phishing attacks and malware distribution, leveraging the trust users place in a legitimate domain. Open redirect vulnerabilities are often exploited in social engineering attacks to increase their effectiveness.

In this case, the vulnerability is due to insufficient validation of the redirect parameter in the oauth2callback.php file of the Analytics Insights plugin. The lack of strict input validation allows an attacker to alter the URL to which a user is redirected. By crafting a malicious URL, an attacker could redirect users to external domains under their control. The attack does not require authentication, making it more likely to be exploited in phishing campaigns. The vulnerable endpoint accepts user input via the `state` parameter, which is manipulated to point to a different site. Protecting against this requires ensuring that only valid and intended URLs are used for redirection.

If exploited, the Open Redirect vulnerability could lead to several negative consequences for affected websites and their users. Users could be directed to phishing sites that closely mimic legitimate services to steal credentials or personal information. Websites could also face reputation damage if users are repeatedly redirected to unsafe sites from a trusted domain. Such incidents could result in loss of user trust and a decrease in site traffic. Additionally, widespread exploitation could trigger blacklisting by security services or browsers, further affecting site accessibility. In severe cases, users might be exposed to drive-by downloads, risking malware infections just by visiting the malicious link.

REFERENCES

Solution Advice
  • Ensure to update Analytics Insights for Google Analytics 4 to version 6.3 or later, where this issue has been fixed.
  • Implement strict validation for redirect parameters to only allow predefined, safe URLs.
  • Regularly audit your website plugins and extensions for any security vulnerabilities.
  • Utilize security plugins or tools that can scan and identify open redirect vulnerabilities within your website.
  • Educate your users about the risks of clicking on untrusted links, even if they originate from seemingly legitimate sites.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.