PT-2026-43536 · Wmark · Cdn Linker Lite

Muhammad Afnaan

·

Published

2026-05-27

·

Updated

2026-05-27

·

CVE-2026-8941

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the ossdl off options() function. This makes it possible for unauthenticated attackers to update the plugin's settings — including the CDN URL used to rewrite all static asset references on the site — via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-8941

Affected Products

Cdn Linker Lite