Junglewise Threat Intelligence

CVE-2026-8902: WordPress AJAX Report Comments CSRF in rc_options_page

CVE-2026-8902 · Severity: medium · CVSS 4.3 · Published 2026-06-09

Vendors: Wordpress.

Executive brief

The AJAX Report Comments plugin for WordPress, which allows users to flag inappropriate comments, contains a security flaw that could allow an attacker to change the plugin's settings. By tricking a site administrator into clicking a malicious link, an attacker can modify notification email addresses, alert messages, and comment thresholds. This could lead to the redirection of administrative alerts to an attacker-controlled email or the disruption of the site's comment moderation system.

Technical details

The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the rc_options_page function. An unauthenticated attacker can exploit this by inducing a site administrator to perform an action, such as clicking a crafted link, which triggers a forged request to the server. Successful exploitation allows the attacker to modify various plugin configurations, including the notification email address, email subject/body, comment thresholds, and UI text. This vulnerability affects all versions up to and including 2.0.4.

Affected products

  • WordPress AJAX Report Comments up to, and including, 2.0.4

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References