GTM Kit – Google Tag Manager & GA4 integration

GTM Kit – Google Tag Manager & GA4 integration has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).

The one issue recorded for GTM Kit – Google Tag Manager & GA4 integration has a vendor fix available, so running the current release closes it.

All of these findings were reported by Psai. GTM Kit – Google Tag Manager & GA4 integration is installed on roughly 30,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all GTM Kit – Google Tag Manager & GA4 integration vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2025-31001

GTM Kit <= 2.4.0 - Unauthenticated Sensitive Information Exposure

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
GTM Kit – Google Tag Manager & GA4 integration banner
Latestv2.18.1

GTM Kit – Google Tag Manager & GA4 integration

TLA Media

Author

TLA Media

4.8(20)
96/100
Last Updated
2026-08-24 (19d ago)
Active Installs
30,000+
Downloads
737,488
Requires WP
6.9+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2022-09-06 (4y ago)

GTM Kit puts the Google Tag Manager container code on your website so that you don’t need to touch any code. It also pushes data from WooCommerce, Easy Digital Downloads (EDD) and Contact Form 7 to the data layer for use with for Google Analytics 4, Facebook and other GTM tags. The goal of GTM Kit is to provide a flexible tool for generating the data layer for Google Tag Manager. It is easy to use and doesn’t require any coding, but it allows developers to customize the plugin as needed. The settings are organised around what you are trying to do (Setup, Events & data layer, Commerce, Consent & privacy, and Tools), so related options live together and the setting you need is quick to find. Know when your tracking breaks Tracking fails quietly. A caching plugin strips the container out of the page, a second plugin loads it a second time, a staging copy reports into your live property, and nothing on the settings screen says so. GTM Kit checks one of your own pages once a day, the way a visitor receives it, and tells you when nothing on your site is loading your container, or when your pages load tracking twice. Where it recognises the plugin or tool adding the second copy, it names it. Two checks in WordPress’s own Site Health screen report whether your container is set up and reaching your pages, and whether consent is configured. A GTM Kit section on the Info tab lists your whole configuration on one screen and copies it into a support request with one click. On sites WordPress reports as staging, development or local, GTM Kit leaves the container out, so test traffic never reaches your live analytics. The data layer is still built there, and a setting loads the container anyway when you are measuring a test site on purpose. eCommerce events tracked with Google Analytics 4 The following GA4 events are automatically included in the dataLayer: WooCommerce view_item_list select_item view_item add_to_wishlist [Premium] add_to_cart view_cart remove_from_cart begin_checkout add_shipping_info add_payment_info purchase refund [Premium] order_paid [Premium] order_processing [Premium] order_completed [Premium] order_refunded [Premium] subscription_started [Premium] Unlock all features with GTM Kit Premium. Easy Digital Downloads view_item add_to_cart begin_checkout purchase Flexible container implementation Depending on how you use Google Tag Manager you can delay the loading of the container script until the browser is idle. This may be relevant to you be if are focusing on pagespeed. You may enter a custom domain name if you are using a custom server side GTM (sGTM) container for tracking. It’s also possible to specify a custom loader. GTM Kit has full support for Stape server GTM hosting. You can also exclude specific pages from GTM entirely. Add URL patterns on the Container settings page and GTM Kit holds back the container, the noscript fallback, and its data layer scripts on matching pages. Useful for third-party checkout iframes, partner-hosted subpages, and in-app webview routes that run their own tracking. Glob patterns are supported by default, with optional regex for advanced matching. Moving from another Google Tag Manager plugin GTM Kit imports settings from Google Tag Manager for WordPress, Google Tag Manager for WooCommerce, Metronet Tag Manager and other GTM plugins, at any time, from the Tools page. Your container ID, data layer variables, Consent Mode defaults, excluded user roles and container environment come across in one step. Before anything is written you see exactly which of your settings will be replaced, and only settings the other plugin actually configured are touched. Post data You may specify which post data elements you wish to include in the dataLayer for use in Google Tag Manager. – Post type: include the type of the current post or archive page. – Page type: include a defined page type. I.e. post, page, product, category, cart, checkout etc. – Categories: include the categories of the current post or archive page. – Tags: include the tags of the current post or archive page. – Post title: include the post title of the current post. – Post ID: include the Post ID of the current post. – Post date: include the post date. – Post author name: include the post author name. – Post author ID: include the post author ID.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C