VYPR
Medium severity4.3NVD Advisory· Published Jan 23, 2026· Updated Apr 28, 2026

CVE-2026-24596

CVE-2026-24596

Description

Cross-Site Request Forgery (CSRF) vulnerability in marynixie Related Posts Thumbnails Plugin for WordPress related-posts-thumbnails allows Cross Site Request Forgery.This issue affects Related Posts Thumbnails Plugin for WordPress: from n/a through <= 4.3.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in Related Posts Thumbnails plugin for WordPress (≤4.3.2) allows attackers to force privileged users to execute unwanted actions.

The Related Posts Thumbnails plugin for WordPress, versions up to and including 4.3.2, contains a Cross-Site Request Forgery (CSRF) vulnerability. This flaw arises from insufficient validation of request origins, allowing an attacker to craft malicious requests that are executed under the authentication of a higher privileges of an authenticated administrator or other privileged user [1].

Exploitation requires user interaction: a privileged user must be tricked into clicking a malicious link, visiting a crafted page, or submitting a form while authenticated to the WordPress site. No additional authentication is needed for the attacker beyond the victim's existing session [1].

Successful exploitation could enable an attacker to perform unauthorized actions on behalf of the victim, such as changing plugin settings or performing other administrative operations, without the victim's consent. The CVSS score of 4.3 (Medium) reflects the need for user interaction and the limited direct impact on data confidentiality or access to sensitive data [1].

The vulnerability is addressed in version 4.3.3 of the plugin. Users are strongly advised to update to this version or later. Patchstack users can enable auto-updates for vulnerable plugins. As a general precaution, administrators should avoid clicking suspicious links while logged into their WordPress dashboard [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.