Google Analytics Opt-Out
Google Analytics Opt-Out has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Google Analytics Opt-Out has a vendor fix available, so running the current release closes it.
All of these findings were reported by Rio Darmawan. Google Analytics Opt-Out is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.2.11.
CVE-2023-25712Google Analytics Opt-Out <= 2.3.4 - Authenticated (Admin+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Google Analytics Opt-Out
Author
wp-buddy
This plugin provides opt-out functionality for Google Analytics by setting a cookie that prevents analytics.js or gtag.js from collecting data. The new GDPR rules require an opt-out. Works perfectly with the [Google Analytics by MonsterInsights Plugin] (https://wordpress.org/plugins/google-analytics-for-wordpress/ “Google Analytics by MonsterInsights Plugin”). However, the plugin is not required to configure the opt-out feature. Just enter your UA or GA code manually. And that’s it! The free and pro versions have now been merged. So now you can also activate a banner! Have fun with it!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C