PT-2026-4580 · WordPress · Star Review Manager

Muhammad Afnaan

·

Published

2026-01-24

·

Updated

2026-01-24

·

CVE-2026-1076

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Star Review Manager plugin for WordPress versions up to and including 1.2.2
Description The Star Review Manager plugin for WordPress is susceptible to Cross-Site Request Forgery due to the absence of nonce validation on the settings page. This allows unauthenticated attackers to modify the plugin’s CSS settings by forging requests, provided they can deceive a site administrator into performing an action, such as clicking a link.
Recommendations Update the Star Review Manager plugin to a version newer than 1.2.2.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-1076

Affected Products

Star Review Manager