Executive brief
The Bigfishgames Syndicate plugin for WordPress, which is used to integrate game syndication features into websites, contains a security flaw that could allow an attacker to change the plugin's settings. By tricking a site administrator into clicking a malicious link or visiting a compromised page, an attacker can remotely reset or modify the plugin's configuration. This could disrupt the intended functionality of the plugin on the affected website.
Technical details
The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the bigfishgames_syndicate_submenu() function. This vulnerability affects all versions up to and including 1.2. An unauthenticated attacker can exploit this by inducing a site administrator to perform an action, such as clicking a link, which triggers a forged request to the vulnerable function. Successful exploitation allows the attacker to reset or modify the plugin's configuration settings. The attack requires network access and user interaction from an authenticated administrator.
Affected products
- Bigfishgames Bigfishgames Syndicate up to, and including, 1.2
Timeline
- 2026-05-20: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/bigfishgames-syndicate/tags/1.2/bigfishgames-syndicate.php
- https://plugins.trac.wordpress.org/browser/bigfishgames-syndicate/tags/1.2/bigfishgames-syndicate.php
- https://plugins.trac.wordpress.org/browser/bigfishgames-syndicate/trunk/bigfishgames-syndicate.php
- https://plugins.trac.wordpress.org/browser/bigfishgames-syndicate/trunk/bigfishgames-syndicate.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/67877a2e-a45d-4674-b749-05d9217ef6bf?source=cve