First published: Thu Sep 29 2022(Updated: )
Auth. (admin+) Stored Cross-Site Scripting (XSS) in Fatcat Apps Analytics Cat plugin <= 1.0.9 on WordPress.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fatcatapps Analytics Cat | <=1.0.9 |
Update to 1.1.0 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-40311 is medium with a severity value of 4.8.
The Fatcat Apps Analytics Cat plugin version 1.0.9 or lower on WordPress is affected by CVE-2022-40311.
As a stored cross-site scripting (XSS) vulnerability, CVE-2022-40311 can be exploited by an authenticated admin or higher user to execute malicious scripts on affected websites.
Yes, patches and fixes are available for CVE-2022-40311. You can find more information and download them from the following references: [Link 1](https://patchstack.com/database/vulnerability/analytics-cat/wordpress-analytics-cat-plugin-1-0-9-authenticated-stored-cross-site-scripting-xss-vulnerability?_s_id=cve) and [Link 2](https://wordpress.org/plugins/analytics-cat/#developers).
The Common Weakness Enumeration (CWE) ID of CVE-2022-40311 is CWE-79.