Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Byybora
Byybora google Pagerank Display Wordpress Wordpress wordpress |
|
| Vendors & Products |
Byybora
Byybora google Pagerank Display Wordpress Wordpress wordpress |
|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4. This is due to missing nonce validation in the gpdisplay_option() function, which handles the plugin settings page. The settings form does not include a wp_nonce_field(), and the form handler does not call check_admin_referer() or wp_verify_nonce() before processing the POST request. This makes it possible for unauthenticated attackers to trick a logged-in administrator into submitting a crafted request that changes the plugin's settings (stored via update_option()), such as the display style used to render the PageRank badge. | |
| Title | Google PageRank Display <= 1.4 - Cross-Site Request Forgery to Settings Update via Settings Page | |
| Weaknesses | CWE-352 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-22T12:07:22.564Z
Reserved: 2026-04-14T18:03:33.157Z
Link: CVE-2026-6294
Updated: 2026-04-22T12:07:18.863Z
Status : Deferred
Published: 2026-04-22T09:16:26.677
Modified: 2026-04-22T20:22:50.570
Link: CVE-2026-6294
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:43:50Z