SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-9731

MEDIUM · CVSS 4.3 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery due to inadequate nonce validation in the plugin_settings function, affecting all versions up to 1.0.9. This vulnerability allows unauthenticated attackers to modify the plugin's notification text and CSS settings, potentially injecting malicious content that is displayed on the frontend if an administrator is tricked into executing a crafted request. WordPress site administrators using this plugin should prioritize applying updates to mitigate the risk of exploitation.

CVE
CVE-2026-9731
Severity
MEDIUM
CVSS
4.3
EPSS
0.13%
WordPress

Original NVD Description

The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to missing or incorrect nonce validation on the plugin_settings function. This makes it possible for unauthenticated attackers to update the plugin's notification text and CSS settings (wp_non_js_notification_text and wp_non_js_notification_css), injecting arbitrary content that is echoed unescaped on the frontend via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.