WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in GTM4WP – A Google Tag Manager (GTM) plugin for WordPress

Advanced tag management for WordPress with Google Tag Manager

3Reported vulnerabilities
7.2Highest CVSS score
1.22.5Latest version
700,000+Active installs

What to do now

Update GTM4WP – A Google Tag Manager (GTM) plugin for WordPress to 1.22.4 or later. 3 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 4, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2022-1961 Medium 4.8 1.1% Before 1.15.2 1.15.2 June 13, 2022
CVE-2026-16597 High 7.2 0.2% 0 to 1.22.3 (inclusive) 1.22.4 July 29, 2026
WF-79a41b84-2e19-46eb-9f6b-5155da0b15cc High 7.2 1.15 and earlier 1.15.1 May 12, 2022

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.