Junglewise Threat Intelligence

CVE-2026-3191: teckel Minify HTML CSRF in minify_html_menu_options

CVE-2026-3191 · Severity: medium · CVSS 5.4 · Published 2026-03-31

Executive brief

The Minify HTML plugin for WordPress, which is used to optimize website performance by shrinking code, contains a security flaw that allows attackers to change its settings. By tricking a site administrator into clicking a malicious link, an attacker can remotely modify how the plugin functions. This could lead to unauthorized changes in site behavior or minor service disruptions.

Technical details

The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the 'minify_html_menu_options' function. This vulnerability exists in all versions up to and including 2.1.12. An unauthenticated attacker can exploit this by inducing a site administrator to perform an action, such as clicking a link or visiting a malicious website, while authenticated to the WordPress dashboard. Successful exploitation allows the attacker to modify the plugin's configuration settings. A patch appears to be available in subsequent versions (changeset 3486011).

Affected products

  • teckel Minify HTML up to, and including, 2.1.12

Timeline

  • 2026-03-31: disclosed
  • 2026-03-31: advisory

References