Cross-Site Request Forgery Vulnerability in EmergencyWP Plugin by WordPress
CVE-2026-9732
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 June 2026
What is CVE-2026-9732?
The EmergencyWP plugin, utilized for vital management in WordPress, is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in its settings save handler. This flaw allows malicious actors to send forged requests that can lead to unauthorized alterations of critical plugin settings. Specifically, an attacker could manipulate access roles, modify the data-erasure-on-uninstall flag, and change timing values and email configurations—all requiring only that they trick an administrator into clicking a malicious link.
Affected Version(s)
EmergencyWP – Dead Man's switch & legacy deliverance 0 <= 1.4.2