Cross-Site Request Forgery in Purchase Button for Affiliate Link by WordPress
CVE-2026-1073
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 March 2026
What is CVE-2026-1073?
The Purchase Button For Affiliate Link plugin for WordPress exhibits a Cross-Site Request Forgery vulnerability in all versions up to and including 1.0.2. This vulnerability arises from the absence of nonce validation in the settings page form handler, specifically located in 'inc/purchase-btn-options-page.php'. Consequently, this flaw allows unauthenticated attackers to alter plugin settings by persuading a site administrator to execute a specific action, such as clicking on a malicious link, thus compromising the security of the WordPress site.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Purchase Button For Affiliate Link * <= 1.0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved