Cross-Site Request Forgery Vulnerability in Tectite Forms Plugin for WordPress
CVE-2026-9599
4.3MEDIUM
What is CVE-2026-9599?
The Tectite Forms plugin for WordPress suffers from a Cross-Site Request Forgery vulnerability due to inadequate nonce validation in the admin_init function. This flaw allows unauthenticated attackers to alter plugin settings, such as the tectite_forms_button option, by tricking a site administrator into executing a malicious request, such as clicking on a deceptive link.
Affected Version(s)
Tectite Forms 0 <= 1.3