CVE-2025-12521

Analytify Pro <= 7.0.3 - Unauthenticated Information Exposure

The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0.3 via the Analytify Tag HTML details. This makes it possible for unauthenticated attackers to extract usernames from source code. While we generally do not assign CVE IDs to username exposure issues, this vendor has specifically requested we consider it a vulnerability.


We have discovered 8,942 live websites that are affected by CVE-2025-12521.

Run a Free Instant Scan




Affected Software

Product  Analytify
Category Analytics
Vulnerable Domains8,942 live websites (68% of Analytify install base)
Vulnerable Versions
  • from 0 through 7.0.3
Vulnerable Versions Count47 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Oct 31, 2025
  • Updated - Nov 3, 2025

Credits

  • WPBrigade Support (finder)

Website Distribution by Country

Number of websites using CVE-2025-12521
United States4,070 websites



GB650 websites
France592 websites
Germany372 websites
Norway346 websites
Poland242 websites
Netherlands218 websites
Australia204 websites
New Zealand183 websites
Canada168 websites

Website Distribution by TLD

Number of websites using CVE-2025-12521
.com4,377 websites
.org617 websites
.co.uk341 websites
.fr299 websites
.net223 websites
.pl184 websites
.nl177 websites
.com.au177 websites
.de138 websites
.ca104 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-12521

Top websites that are affected by CVE-2025-12521. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.com United States**,***
************.org United States**,***
****.community United States**,***
**************.com United States**,***
********.**.uk GB**,***
***.***.my Malaysia**,***
*********.com Cyprus***,***
******.org United States***,***
****.***.br Brazil***,***
*****.org United States***,***
See full domain list

FAQ

CVE-2025-12521 is Exposure of Sensitive Information to an Unauthorized Actor in Analytify
A total of 8,942 websites have been identified as vulnerable to CVE-2025-12521, based on global website indexing conducted by WebTechSurvey.
The Analytify is affected by the CVE-2025-12521 vulnerability.
Analytify versions up to and including 7.0.3 are vulnerable to CVE-2025-12521.