PT-2026-45715 · WordPress · Remove Nofollow Commenter Url
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Remove NoFollow Commenter URL versions prior to 1.1
Description
The plugin is subject to Cross-Site Request Forgery due to missing or incorrect nonce validation in the
gmz comment settings save() function. This allows unauthenticated attackers to modify the comment-display setting by tricking a site administrator into clicking a malicious link.Recommendations
Update to a version later than 1.0.
As a temporary workaround, restrict access to the plugin settings to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Remove Nofollow Commenter Url