Cross-Site Request Forgery Vulnerability in Publish 2 Ping.fm Plugin for WordPress
CVE-2026-6702

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 May 2026

What is CVE-2026-6702?

The Publish 2 Ping.fm plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to inadequate nonce validation in the settings page. This allows unauthenticated attackers to exploit the vulnerability by tricking site administrators into clicking malicious links, potentially leading to unauthorized settings updates and injection of harmful scripts. Affected versions include all releases up to and including 1.1. It is crucial for administrators to ensure their sites are updated to mitigate this risk and protect against possible exploitation.

Affected Version(s)

Publish 2 Ping.fm 0 <= 1.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Nur Ibnu Hubab
.