Cross-Site Request Forgery in AJAX Report Comments Plugin for WordPress
CVE-2026-8902
4.3MEDIUM
What is CVE-2026-8902?
The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to inadequate nonce validation in its functions. Attackers can exploit this vulnerability to craft unauthorized requests that alter plugin settings. If an administrator is tricked into clicking a malicious link, the attacker can modify crucial components such as link text, comment thresholds, email notifications, and more, thereby compromising the plugin's integrity and the security of the WordPress site.
Affected Version(s)
AJAX Report Comments 0 <= 2.0.4