Junglewise Threat Intelligence

CVE-2026-8906: WP Promoter WordPress plugin CSRF in admin-wp-promoter.php

CVE-2026-8906 · Severity: medium · CVSS 6.1 · Published 2026-05-27

Executive brief

The WP Promoter plugin for WordPress, used for site promotion and marketing, contains a security flaw that could allow an attacker to change site settings. By tricking a site administrator into clicking a malicious link, an attacker can silently modify configurations or inject harmful scripts into the website. This could lead to unauthorized site changes or the redirection of visitors to malicious websites.

Technical details

The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to and including 1.3. The vulnerability stems from missing or incorrect nonce validation on certain functions within the admin-wp-promoter.php file. An unauthenticated remote attacker can exploit this by crafting a malicious request and social engineering a site administrator into executing it (e.g., via a phishing link). Successful exploitation allows the attacker to update plugin settings and potentially perform Stored Cross-Site Scripting (XSS) by injecting malicious scripts into the site's configuration.

Affected products

  • WP Promoter WP Promoter up to, and including, 1.3

Timeline

  • 2026-05-27: disclosed: Vulnerability published by Wordfence and NVD.

References

Related threats