VYPR
Medium severity4.3NVD Advisory· Published Feb 3, 2026· Updated Apr 15, 2026

CVE-2026-24966

CVE-2026-24966

Description

Cross-Site Request Forgery (CSRF) vulnerability in Copyscape Copyscape Premium copyscape-premium allows Cross Site Request Forgery.This issue affects Copyscape Premium: from n/a through <= 1.4.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A CSRF vulnerability in Copyscape Premium plugin up to version 1.4.1 allows attackers to force privileged users into unwanted actions.

Vulnerability

Overview

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Copyscape Premium plugin for WordPress, affecting versions from n/a through 1.4.1. The flaw arises from insufficient validation of request origins, enabling an attacker to craft malicious requests that are executed under the authentication of a higher-privileged user [1].

Exploitation

Details

To exploit this vulnerability, an attacker must trick a privileged user (such as an administrator or editor) into performing an action such as clicking a malicious link or visiting a crafted page. No direct authentication is required for the attacker, but the victim must be logged into the WordPress site at the time of the attack [1].

Impact

Successful exploitation could allow an attacker to force the victim to execute unintended actions, such as changing plugin settings or performing other administrative tasks, under the victim's current session. This can lead to unauthorized modifications or data exposure [1].

Mitigation

The vulnerability has been addressed in version 1.4.2 of the plugin. Users are strongly advised to update immediately. For those unable to update, consulting a hosting provider or web developer is recommended security measures is advised. Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.