PT-2026-31099 · WordPress · Quran Translations
Muhammad Afnaan
·
Published
2026-04-08
·
Updated
2026-04-13
·
CVE-2026-4141
CVSS v3.1
4.3
Medium
| AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Quran Translations plugin for WordPress versions up to and including 1.7
Description
The plugin is susceptible to Cross-Site Request Forgery due to the absence of nonce validation in the
quran playlist options() function. This function handles the plugin's settings page and processes POST requests to update plugin options via update option() without verifying the authenticity of the request. An unauthenticated attacker can modify plugin settings, such as display options for PDF, RSS, podcast, media player links, playlist title, and playlist code, by forging a request and tricking a site administrator into performing an action.Recommendations
Update the plugin to a version newer than 1.7.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quran Translations