SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-61956

HIGH · CVSS 7.1 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ووسلام – همگام سازی ووکامرس و باسلام sync-basalam plugin, affecting versions up to and including 1.9.1. This flaw could allow an attacker to perform unauthorized actions on behalf of authenticated users, potentially compromising sensitive data or altering user settings. Organizations using this plugin should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-61956
Severity
HIGH
CVSS
7.1
EPSS
0.11%

Original NVD Description

Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام &#8211; همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1.