SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-8616

MEDIUM · CVSS 5.3 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable due to inadequate capability checks and nonce validation, allowing unauthorized users to modify data through the fense_bpvt_save_settings() function. This vulnerability enables unauthenticated attackers to delete critical plugin options and transients, potentially disrupting the plugin's functionality and API key management. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access and data manipulation.

CVE
CVE-2026-8616
Severity
MEDIUM
CVSS
5.3
EPSS
0.23%
WordPress

Original NVD Description

The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to both wp_ajax_* and wp_ajax_nopriv_* hooks and unconditionally calls delete_option() on four plugin options and delete_transient() on three transients tied to the plugin's API key cache and settings. This makes it possible for unauthenticated attackers to delete plugin options and transients, effectively resetting the plugin's API key/data cache and forcing the plugin to refetch state.