Cross-Site Request Forgery Vulnerability in WP AutoBuzz Plugin for WordPress
CVE-2026-8911

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 May 2026

What is CVE-2026-8911?

The WP AutoBuzz plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) attacks across all versions up to and including 1.1.1. This vulnerability stems from inadequate nonce validation in its implementation. An unauthenticated attacker may exploit this flaw, enabling them to alter settings or inject malicious scripts by persuading an administrator to execute an undesired action, such as clicking a deceptive link. This oversight allows attackers to bypass WordPress's DISALLOW_UNFILTERED_HTML protection, as unsanitized inputs are directly written via the update_option function, circumventing WordPress’s standard content handling processes.

Affected Version(s)

WP AutoBuzz 0 <= 1.1.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Nur Ibnu Hubab
.