PT-2026-51689 · WordPress · Osiris Signature Banner

CVE-2026-8905

·

Published

2026-06-24

·

Updated

2026-07-02

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Osiris Signature Banner versions prior to 0.6
Description The Osiris Signature Banner plugin for WordPress contains a Cross-Site Request Forgery (CSRF) flaw. This occurs because of missing or incorrect nonce validation—a security token used to ensure that a request was intentionally sent by the user—on a function. Unauthenticated attackers can exploit this by tricking a site administrator into clicking a malicious link, allowing the attacker to update settings and inject malicious web scripts via a forged request.
Recommendations Update the plugin to version 0.6 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8905

Affected Products

Osiris Signature Banner