Fatcatapps develops a suite of WordPress plugins and web-based tools spanning pricing tables, analytics, form handling, and email-marketing integrations, positioning them across a broad ecosystem of small-business and publisher sites. The recurring vulnerability profile centers on web-application input-handling and state-management weaknesses, particularly cross-site scripting and CSRF flaws that reflect the plugin-based and user-generated-content context of WordPress deployments, alongside a meaningful tendency toward public exploit availability. Defenders should prioritize updating affected WordPress installations and review plugin configurations for user-input sanitization; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fatcatapps over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24922CRITICAL The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to ma | Dec 13, 2021 | 9.0 | 27 | NO | NO |
CVE-2022-1904MEDIUM The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticat | Jun 27, 2022 | 6.1 | 26 | NO | YES |
CVE-2023-5098HIGH The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the | Oct 31, 2023 | 8.1 | 23 | NO | NO |
CVE-2021-25098MEDIUM The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary | Mar 7, 2022 | 6.5 | 22 | NO | NO |
CVE-2025-59549MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps GetResponse Forms getresponse allows Stored XSS.This issue affects | Sep 22, 2025 | 6.5 | 21 | NO | NO |
CVE-2025-26992HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing Page Cat landing-page-cat allows Reflected XSS.This issue a | Apr 15, 2025 | 7.1 | 21 | NO | NO |
CVE-2025-24615HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Analytics Cat analytics-cat allows Reflected XSS.This issue affects | Feb 14, 2025 | 7.1 | 21 | NO | NO |
CVE-2025-24576HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing Page Cat landing-page-cat allows Reflected XSS.This issue a | Feb 3, 2025 | 7.1 | 20 | NO | NO |
CVE-2022-40311MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) in Fatcat Apps Analytics Cat plugin <= 1.0.9 on WordPress. | Oct 21, 2022 | 4.8 | 19 | NO | NO |
CVE-2021-36866MEDIUM Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Easy Pricing Tables plugin <= 3.1.2 at WordPress. | Jun 2, 2022 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fatcatapps.
Media articles that mention a CVE ID that affects a product developed by Fatcatapps — matched by CVE ID, not by vendor name.