CSRF Token Generation Flaw in WordPress Plugin by Affected Vendor
CVE-2026-19636

6MEDIUM

Key Information:

Vendor
CVE Published:
14 August 2026

What is CVE-2026-19636?

A vulnerability has been detected in the methodology for generating CSRF tokens, which are critical for ensuring secure transactions. The initial token generation process utilized a predictable method, thereby diminishing their capacity as a reliable security measure. This issue has been proactively addressed through enhancements in the randomness and entropy associated with token generation, significantly bolstering the security posture against CSRF attacks.

Affected Version(s)

Security Center Linux 0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.