PT-2026-43536 · Wmark+1 · Cdn Linker Lite+1
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CDN Linker lite versions prior to 1.3.2
Description
Cross-Site Request Forgery occurs due to missing or incorrect nonce validation in the
ossdl off options() function. This allows unauthenticated attackers to update plugin settings, such as the CDN URL used to rewrite static asset references, by tricking a site administrator into clicking a malicious link.Recommendations
Update to a version newer than 1.3.1.
As a temporary workaround, restrict access to the
ossdl off options() function to minimize the risk of exploitation.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cdn Linker Lite
Ossdl-Cdn-Off-Linker