PT-2026-45712 · WordPress · Tectite Forms

·

CVE-2026-9599

·

Published

2026-06-02

·

Updated

2026-06-11

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tectite Forms versions prior to 1.4
Description The Tectite Forms plugin for WordPress is subject to Cross-Site Request Forgery due to missing or incorrect nonce validation in the admin init() function. A nonce is a unique token used to verify that a request was intentionally sent by the user. This flaw allows unauthenticated attackers to modify plugin settings, such as the tectite forms button option, by tricking a site administrator into clicking a malicious link.
Recommendations Update the plugin to a version later than 1.3. As a temporary workaround, restrict administrative access to the WordPress dashboard to trusted networks to minimize the risk of forged requests.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9599

Affected Products

Tectite Forms