Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 27 May 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wmark
Wmark cdn Linker Lite Wordpress Wordpress wordpress |
|
| Vendors & Products |
Wmark
Wmark cdn Linker Lite Wordpress Wordpress wordpress |
Wed, 27 May 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the ossdl_off_options() function. This makes it possible for unauthenticated attackers to update the plugin's settings — including the CDN URL used to rewrite all static asset references on the site — via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Title | CDN Linker lite <= 1.3.1 - Cross-Site Request Forgery to Plugin Settings Update | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-27T10:37:30.063Z
Reserved: 2026-05-19T12:05:08.546Z
Link: CVE-2026-8941
Updated: 2026-05-27T10:37:25.501Z
Status : Deferred
Published: 2026-05-27T07:16:18.687
Modified: 2026-06-17T11:04:38.263
Link: CVE-2026-8941
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:07:30Z