Cross-Site Request Forgery in Google PageRank Display Plugin for WordPress
CVE-2026-6294
4.3MEDIUM
What is CVE-2026-6294?
The Google PageRank Display plugin for WordPress is exposed to Cross-Site Request Forgery due to inadequate nonce validation in its settings handling function. This flaw allows unauthenticated attackers to exploit logged-in administrators, enabling them to submit malicious requests that alter the plugin's settings, including the display style for the PageRank badge. The settings form's lack of a nonce field, combined with missing checks for request validity, creates a serious security risk that could compromise the integrity of the site.
Affected Version(s)
Google PageRank Display 0 <= 1.4