Cross-Site Request Forgery Vulnerability in Laiser Tag Plugin for WordPress
CVE-2026-9722

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 June 2026

What is CVE-2026-9722?

The Laiser Tag plugin for WordPress exhibits a vulnerability due to inadequate nonce validation within the addOptionsPageFields function. This allows unauthenticated attackers to manipulate plugin settings through forged requests, potentially altering critical configuration elements such as the API key and tag settings. By tricking site administrators into executing malicious actions, security is compromised, making it essential for users to apply security measures to safeguard their installations.

Affected Version(s)

Laiser Tag 0 <= 1.2.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

swat
.