Executive brief
PublishPress Series is a WordPress plugin used to organize and manage content series on WordPress sites. This vulnerability allows attackers to trick logged-in administrators or editors into performing unintended actions (such as modifying content, changing settings, or deleting series) by luring them to a malicious webpage. No authentication is required on the attacker's side, making it a low-barrier attack vector.
Technical details
This is a Cross-Site Request Forgery (CSRF) vulnerability affecting PublishPress Series plugin versions up to and including 3.1.3. The plugin fails to properly validate anti-CSRF tokens on certain requests, allowing an unauthenticated attacker to craft a malicious webpage that, when visited by an authenticated WordPress user with sufficient privileges, will execute unintended actions on the target site. The attack requires user interaction (the victim must visit the attacker's page while logged into WordPress). The vulnerability has been patched in version 3.1.4 and later.
Affected products
- PublishPress Series <=3.1.3
Timeline
- 2026-09-16: disclosed: Published by Patchstack
- 2026-09-16: patched: Fixed in version 3.1.4