VYPR
High severity7.1NVD Advisory· Published May 25, 2026

CVE-2026-39436

CVE-2026-39436

Description

Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery.

This issue affects CformsII: from n/a through 15.1.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF in WordPress CformsII plugin up to 15.1.3 allows attackers to force privileged users to execute unwanted actions; fixed in 15.1.4.

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the bgermann CformsII plugin for WordPress, affecting versions from n/a through 15.1.3. The plugin fails to properly validate or verify requests made by authenticated users, allowing an attacker to craft a malicious request that, when executed by an authenticated administrator, performs unintended actions within the plugin's context.

Exploitation

An attacker must trick a privileged user (e.g., an administrator) into clicking a malicious link or visiting a crafted page while the user is logged into WordPress. No authentication is required for the attacker; the forged request is executed under the victim's session. The attack requires user interaction, as the victim must perform an action such as clicking a link or submitting a form.

Impact

Successful exploitation allows the attacker to force the victim to perform actions like modifying plugin settings, creating or deleting users, or altering site configurations. This can lead to privilege escalation, data manipulation, or complete site compromise, depending on the permissions of the victim.

Mitigation

The vulnerability is fixed in version 15.1.4 of the CformsII plugin. Users should update to this version or later immediately. Patchstack users can enable auto-update for vulnerable plugins. No workaround is documented; updating is the recommended action [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.