Cross-Site Request Forgery Vulnerability in EmergencyWP Plugin by WordPress
CVE-2026-9732

4.3MEDIUM

What is CVE-2026-9732?

The EmergencyWP plugin, utilized for vital management in WordPress, is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in its settings save handler. This flaw allows malicious actors to send forged requests that can lead to unauthorized alterations of critical plugin settings. Specifically, an attacker could manipulate access roles, modify the data-erasure-on-uninstall flag, and change timing values and email configurations—all requiring only that they trick an administrator into clicking a malicious link.

Affected Version(s)

EmergencyWP – Dead Man's switch & legacy deliverance 0 <= 1.4.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

swat
.