PT-2026-34309 · Byybora · Google Pagerank Display

Published

2026-04-22

·

Updated

2026-04-22

·

CVE-2026-6294

CVSS v3.1

4.3

Medium

AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4. This is due to missing nonce validation in the gpdisplay option() function, which handles the plugin settings page. The settings form does not include a wp nonce field(), and the form handler does not call check admin referer() or wp verify nonce() before processing the POST request. This makes it possible for unauthenticated attackers to trick a logged-in administrator into submitting a crafted request that changes the plugin's settings (stored via update option()), such as the display style used to render the PageRank badge.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-6294

Affected Products

Google Pagerank Display