Junglewise Threat Intelligence

CVE-2026-61956: hamsalam sync-basalam Cross-Site Request Forgery

CVE-2026-61956 · Severity: high · CVSS 7.1 · Published 2026-07-13

Executive brief

A security vulnerability exists in the 'sync-basalam' WordPress plugin, which is used to synchronize WooCommerce stores with the Basalam marketplace. This flaw allows an attacker to trick a logged-in administrator into performing unintended actions on the website, such as changing settings or modifying data, by getting them to click a malicious link. If exploited, this could lead to unauthorized configuration changes or data manipulation within the store's management interface.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the hamsalam 'sync-basalam' (ووسلام – همگام سازی ووکامرس و باسلام) plugin for WordPress due to missing or incorrect nonce validation on administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a site administrator into executing it (e.g., via social engineering or a malicious link). Successful exploitation allows the attacker to perform unauthorized actions with the privileges of the authenticated user, potentially leading to data modification or integrity loss. The issue is fixed in version 1.9.2.

Affected products

  • hamsalam ووسلام – همگام سازی ووکامرس و باسلام (sync-basalam) <= 1.9.1

Timeline

  • 2026-06-12: other: Reported by researcher Ananda Dhakal via Patchstack
  • 2026-07-12: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD dataset
  • 1.9.2: patched: Vulnerability addressed in version 1.9.2

References