Junglewise Threat Intelligence

CVE-2026-7616: Zawgyi Embed CSRF in zawgyi_adminpage function

CVE-2026-7616 · Severity: medium · CVSS 4.3 · Published 2026-05-12

Executive brief

The Zawgyi Embed plugin for WordPress, which helps display specific Burmese fonts, contains a security flaw that could allow an attacker to change the plugin's settings. By tricking a site administrator into clicking a malicious link or visiting a compromised website, an attacker can remotely modify the plugin's CSS configuration. While this does not allow for full site takeover, it can disrupt the site's appearance or layout for visitors.

Technical details

The Zawgyi Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the zawgyi_adminpage function. This vulnerability affects all versions up to and including 2.1.1. An unauthenticated attacker can exploit this by crafting a forged POST request to the options-general.php?page=zawgyi_embed endpoint. If a logged-in administrator interacts with the malicious request (e.g., via social engineering), the attacker can successfully update the 'zawgyi_forceCSS' setting. This is a classic CWE-352 flaw where the application fails to verify that a sensitive request was intentionally initiated by the user.

Affected products

  • Zawgyi Embed Zawgyi Embed Up to and including 2.1.1

Timeline

  • 2026-05-12: disclosed: Vulnerability published on NVD and Wordfence.

References