Junglewise Threat Intelligence

CVE-2026-9731: Wp Js Detect CSRF in plugin_settings function

CVE-2026-9731 · Severity: medium · CVSS 4.3 · Published 2026-07-08

Executive brief

The Wp Js Detect plugin for WordPress, which helps websites detect if a visitor has JavaScript enabled, contains a security flaw that allows attackers to change plugin settings. By tricking a site administrator into clicking a malicious link, an attacker can modify the notification text and styling shown to visitors. This could be used to deface the website or display misleading information to users.

Technical details

The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the plugin_settings function. An unauthenticated attacker can exploit this by inducing a logged-in administrator to submit a forged request, typically via a malicious link or hidden form. Successful exploitation allows the attacker to modify the 'wp_non_js_notification_text' and 'wp_non_js_notification_css' settings. Because these values are echoed unescaped on the site's frontend, this can lead to arbitrary content injection or defacement. The vulnerability affects all versions up to and including 1.0.9.

Affected products

  • wpkuf Wp Js Detect up to, and including, 1.0.9

Timeline

  • 2026-07-08: disclosed: Initial publication of the CVE record.
  • 2026-07-08: advisory

References