CVE-2026-39436
Description
Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery.
This issue affects CformsII: from n/a through 15.1.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CSRF in WordPress CformsII plugin up to 15.1.3 allows attackers to force privileged users to execute unwanted actions; fixed in 15.1.4.
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the bgermann CformsII plugin for WordPress, affecting versions from n/a through 15.1.3. The plugin fails to properly validate or verify requests made by authenticated users, allowing an attacker to craft a malicious request that, when executed by an authenticated administrator, performs unintended actions within the plugin's context.
Exploitation
An attacker must trick a privileged user (e.g., an administrator) into clicking a malicious link or visiting a crafted page while the user is logged into WordPress. No authentication is required for the attacker; the forged request is executed under the victim's session. The attack requires user interaction, as the victim must perform an action such as clicking a link or submitting a form.
Impact
Successful exploitation allows the attacker to force the victim to perform actions like modifying plugin settings, creating or deleting users, or altering site configurations. This can lead to privilege escalation, data manipulation, or complete site compromise, depending on the permissions of the victim.
Mitigation
The vulnerability is fixed in version 15.1.4 of the CformsII plugin. Users should update to this version or later immediately. Patchstack users can enable auto-update for vulnerable plugins. No workaround is documented; updating is the recommended action [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=15.1.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.