PT-2026-34309 · Byybora · Google Pagerank Display
Published
2026-04-22
·
Updated
2026-04-22
·
CVE-2026-6294
CVSS v3.1
4.3
Medium
| AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4. This is due to missing nonce validation in the gpdisplay option() function, which handles the plugin settings page. The settings form does not include a wp nonce field(), and the form handler does not call check admin referer() or wp verify nonce() before processing the POST request. This makes it possible for unauthenticated attackers to trick a logged-in administrator into submitting a crafted request that changes the plugin's settings (stored via update option()), such as the display style used to render the PageRank badge.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Pagerank Display