Cross-Site Request Forgery Vulnerability in Publish 2 Ping.fm Plugin for WordPress
CVE-2026-6702
6.1MEDIUM
What is CVE-2026-6702?
The Publish 2 Ping.fm plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to inadequate nonce validation in the settings page. This allows unauthenticated attackers to exploit the vulnerability by tricking site administrators into clicking malicious links, potentially leading to unauthorized settings updates and injection of harmful scripts. Affected versions include all releases up to and including 1.1. It is crucial for administrators to ensure their sites are updated to mitigate this risk and protect against possible exploitation.
Affected Version(s)
Publish 2 Ping.fm 0 <= 1.1