Junglewise Threat Intelligence

CVE-2026-8424: Remove Yellow BGBOX CSRF in rybb_api_settings

CVE-2026-8424 · Severity: medium · CVSS 4.3 · Published 2026-05-20

Executive brief

The Remove Yellow BGBOX plugin for WordPress, which is used to manage specific site styling or interface elements, contains a security flaw that allows unauthorized changes to its settings. By tricking a site administrator into clicking a malicious link, an attacker can remotely reset or overwrite the plugin's configuration. This could lead to unauthorized changes in how the website appears or functions, potentially disrupting the site's intended design.

Technical details

The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.0. The vulnerability stems from missing or incorrect nonce validation on the 'rybb_api_settings' page. An unauthenticated attacker can exploit this by inducing a site administrator to perform an action, such as clicking a link, which triggers a forged request to the server. Successful exploitation allows the attacker to overwrite or reset the plugin's stored configuration settings. This is classified as CWE-352.

Affected products

  • Remove Yellow BGBOX Remove Yellow BGBOX Up to, and including, 1.0

Timeline

  • 2026-05-20: advisory: NVD publication date

References