Junglewise Threat Intelligence

CVE-2026-6405: Anomify AI WordPress Plugin CSRF to Stored XSS

CVE-2026-6405 · Severity: medium · CVSS 4.3 · Published 2026-05-20

Executive brief

The Anomify AI plugin for WordPress, which provides anomaly detection and alerting services, contains a security flaw that allows attackers to hijack administrative settings. By tricking a site administrator into clicking a malicious link, an attacker can remotely change plugin configurations and inject malicious scripts into the website's management dashboard. This could lead to unauthorized actions being performed in the administrator's browser, potentially compromising the security of the WordPress site.

Technical details

The Anomify AI plugin for WordPress is vulnerable to a CSRF-to-Stored-XSS chain due to missing nonce verification and inadequate output escaping. Specifically, the settings page handler lacks 'check_admin_referer()' and the form does not use 'wp_nonce_field()', allowing unauthenticated attackers to modify plugin settings via a forged cross-origin POST request. Furthermore, the API key field is sanitized using 'sanitize_text_field()', which fails to encode double quotes, and is subsequently rendered in the 'admin_options.php' template via a bare echo without 'esc_attr()'. This allows an attacker to escape the HTML attribute and inject arbitrary JavaScript that executes when an administrator visits the settings page.

Affected products

  • Anomify Anomify AI – Anomaly Detection and Alerting up to and including 0.3.6

Timeline

  • 2026-05-20: disclosed: CVE published by Wordfence and NVD

References