PT-2026-34863 · WordPress · Taqnix
Youcef Hamdani
·
Published
2026-04-24
·
Updated
2026-04-25
·
CVE-2026-3565
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Taqnix versions prior to 1.0.4
Description
The Taqnix plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF), a flaw where an attacker tricks a user into performing actions they did not intend to. This occurs because of missing nonce verification in the
taqnix delete my account() function, specifically where the check ajax referer() call is commented out. Unauthenticated attackers can exploit this to force logged-in non-administrator users to delete their own accounts by inducing them to click a malicious link or visit a compromised page.Recommendations
Update to a version later than 1.0.3.
As a temporary workaround, restrict access to the
taqnix delete my account() function until a patch is applied.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Taqnix