Cross-Site Request Forgery in Remove NoFollow Commenter URL Plugin for WordPress
CVE-2026-9730
4.3MEDIUM
What is CVE-2026-9730?
The Remove NoFollow Commenter URL plugin for WordPress is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in the gmz_comment_settings_save function. This vulnerability allows unauthenticated attackers to exploit it by tricking a site administrator into executing an unintended action, such as clicking a malicious link. By doing so, they can manipulate the plugin's comment-display settings, potentially compromising the security and integrity of the website.
Affected Version(s)
Remove NoFollow Commenter URL 0 <= 1.0