Connect Matomo – Analytics Dashboard for WordPress

Connect Matomo – Analytics Dashboard for WordPress has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2023; all 5 are fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 4 of the records (80%). Other recurring categories include Cross-Site Request Forgery (CSRF).

Every one of the 5 issues recorded for Connect Matomo – Analytics Dashboard for WordPress has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. Connect Matomo – Analytics Dashboard for WordPress is installed on roughly 60,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.0.

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage100%
Open

0

Fixed

5

Get automatic notifications for all Connect Matomo – Analytics Dashboard for WordPress vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8

WP-Matomo Integration (WP-Piwik) <= 1.0.26 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

5 records
Connect Matomo – Analytics Dashboard for WordPress banner
Latestv1.1.10

Connect Matomo – Analytics Dashboard for WordPress

matomoteam

Author

matomoteam

4.5(95)
90/100
Last Updated
2026-08-05 (1mo ago)
Active Installs
60,000+
Downloads
3,339,612
Requires WP
5.0+
Requires PHP
0+
Tested up to
WP 7.0.0
Created
2009-06-04 (18y ago)

Version 1.1.7 includes a security related fix, it is highly recommended to update to this or a later version. If you are not yet using Matomo On-Premise, Matomo Cloud or hosting your own instance of Matomo, please use the Matomo for WordPress plugin. This plugin uses the Matomo API to show your Matomo statistics in your WordPress dashboard. It’s also able to add the Matomo tracking code to your blog and to do some modifications to the tracking code. Additionally, WP-Matomo supports WordPress networks and manages multiple sites and their tracking codes. To use this plugin the Matomo web analytics application is required. If you do not already have a Matomo setup (e.g., provided by your web hosting service), you have two simple options: use either a self-hosted Matomo or a cloud-hosted Matomo by InnoCraft. Requirements: PHP 7.0 (or higher), WordPress 5.0 (or higher), Matomo 4.0 (or higher) Languages: English, Albanian, Chinese, Dutch, French, German, Greek, Hungarian, Italian, Polish, Portuguese (Brazil). Partially supported: Azerbaijani, Belarusian, Hindi, Lithuanian, Luxembourgish, Norwegian, Persian, Romanian, Russian, Spanish, Swedish, Turkish, Ukrainian What is Matomo? Learn more. First steps Learn how to install your own Matomo instance: Requirements, Installation. If you need support about Matomo, please have a look at the Matomo forums. Finally, you can start setting up WP-Matomo. Shortcodes You can use following shortcodes if activated: [wp-piwik module="overview" title="" period="day" date="yesterday"] Shows overview table like WP-Matomo’s overview dashboard. See Matomo API documentation on VisitsSummary.get to get more information on period and day. Multiple data arrays will be cumulated. If you fill the title attribute, its content will be shown in the table’s title. [wp-piwik module="opt-out" language="en" width="100%" height="200px"] Shows the Matomo opt-out Iframe. You can change the Iframe’s language by the language attribute (e.g. de for German language) and its width and height using the corresponding attributes. [wp-piwik module="post" range="last30" key="sum_daily_nb_uniq_visitors"] Shows the chosen keys value related to the current post. You can define a range (format: lastN, previousN or YYYY-MM-DD,YYYY-MM-DD) and the desired value’s key (e.g., sum_daily_nb_uniq_visitors, nb_visits or nb_hits – for details see Matomo’s API method Actions.getPageUrl using a range). [wp-piwik] is equal to [wp-piwik module=”overview” title=”” period=”day” date=”yesterday”]. Credits and Acknowledgements Graphs powered by Chart.js (MIT License). All translators at Transifex and WordPress. Anyone who donates to the WP-Matomo project, including the Matomo team! All users who send me mails containing criticism, commendation, feature requests and bug reports – you help me to make WP-Matomo much better! Thank you all!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C