Cross-Site Request Forgery Vulnerability in Laiser Tag Plugin for WordPress
CVE-2026-9722
4.3MEDIUM
What is CVE-2026-9722?
The Laiser Tag plugin for WordPress exhibits a vulnerability due to inadequate nonce validation within the addOptionsPageFields function. This allows unauthenticated attackers to manipulate plugin settings through forged requests, potentially altering critical configuration elements such as the API key and tag settings. By tricking site administrators into executing malicious actions, security is compromised, making it essential for users to apply security measures to safeguard their installations.
Affected Version(s)
Laiser Tag 0 <= 1.2.5