First published: Tue Nov 08 2022(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Analytify - Google Analytics Dashboard | <4.2.3 |
Update to 4.2.3 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38137 is classified as a high severity Cross-Site Request Forgery (CSRF) vulnerability.
To fix CVE-2022-38137, update the Analytify plugin to version 4.2.3 or later.
CVE-2022-38137 could allow attackers to perform unauthorized actions on behalf of users, potentially compromising user accounts.
If you are using Analytify plugin version 4.2.2 or earlier, your WordPress site is affected by CVE-2022-38137.
CVE-2022-38137 is a Cross-Site Request Forgery vulnerability that allows unauthorized actions through a malicious request.