PT-2026-31099 · WordPress · Quran Translations

Muhammad Afnaan

·

Published

2026-04-08

·

Updated

2026-04-13

·

CVE-2026-4141

CVSS v3.1

4.3

Medium

AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Quran Translations plugin for WordPress versions up to and including 1.7
Description The plugin is susceptible to Cross-Site Request Forgery due to the absence of nonce validation in the quran playlist options() function. This function handles the plugin's settings page and processes POST requests to update plugin options via update option() without verifying the authenticity of the request. An unauthenticated attacker can modify plugin settings, such as display options for PDF, RSS, podcast, media player links, playlist title, and playlist code, by forging a request and tricking a site administrator into performing an action.
Recommendations Update the plugin to a version newer than 1.7.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-4141

Affected Products

Quran Translations