Executive brief
The Remove NoFollow Commenter URL plugin for WordPress, which manages how links in comments are handled for SEO purposes, is vulnerable to a security flaw that allows unauthorized changes to its settings. By tricking a site administrator into clicking a malicious link, an attacker can remotely modify the plugin's comment-display configuration. This could impact how the site handles external links and potentially affect the site's search engine optimization or comment moderation workflow.
Technical details
The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the gmz_comment_settings_save function. An unauthenticated attacker can exploit this by inducing a site administrator to perform an action, such as clicking a crafted link, while authenticated to the WordPress dashboard. Successful exploitation allows the attacker to modify the plugin's comment-display settings. The vulnerability exists in all versions up to and including 1.0. No patch has been confirmed in the provided advisory.
Affected products
- WordPress Plugin Remove NoFollow Commenter URL Up to, and including, 1.0
Timeline
- 2026-06-02: advisory: Initial disclosure by Wordfence and NVD
References
- https://plugins.trac.wordpress.org/browser/remove-nofollow-commenter-link/tags/1.0/gmzxnofollow.php
- https://plugins.trac.wordpress.org/browser/remove-nofollow-commenter-link/tags/1.0/gmzxnofollow.php
- https://plugins.trac.wordpress.org/browser/remove-nofollow-commenter-link/tags/1.0/gmzxnofollow.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c47e170f-f51e-400a-97f3-4da034c193a9?source=cve