First published: Tue Nov 08 2022(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Fatcat Apps Analytics Cat plugin <= 1.0.9 on WordPress allows Plugin Settings Change.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fatcatapps Analytics Cat | <1.1.0 |
Update to 1.1.0 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-27855 is medium, with a severity value of 4.3.
CVE-2022-27855 is a Cross-Site Request Forgery (CSRF) vulnerability in the Fatcat Apps Analytics Cat plugin version 1.0.9 and below on WordPress, which allows for Plugin Settings Change.
To fix CVE-2022-27855, update the Fatcat Apps Analytics Cat plugin to version 1.1.0 or above.
You can find more information about CVE-2022-27855 at the following references: [Patchstack](https://patchstack.com/database/vulnerability/analytics-cat/wordpress-analytics-cat-plugin-1-0-9-plugin-settings-change-via-cross-site-request-forgery-csrf-vulnerability?_s_id=cve) and [WordPress Plugin Directory](https://wordpress.org/plugins/analytics-cat/#developers).
The Common Weakness Enumeration (CWE) ID for CVE-2022-27855 is 352.