PT-2026-51704 · WordPress · Motordesk

·

CVE-2026-9724

·

Published

2026-06-24

·

Updated

2026-07-02

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MotorDesk versions prior to 1.1.3
Description The MotorDesk plugin for WordPress contains a Cross-Site Request Forgery (CSRF) flaw, which occurs when a web application allows an attacker to induce a user to perform actions they do not intend to. This issue is caused by missing or incorrect nonce validation in the motordesk admin home() function. Unauthenticated attackers can exploit this by tricking a site administrator into clicking a link, allowing the attacker to update plugin configuration settings, specifically the search page URI and the custom template directory path.
Recommendations Update to a version later than 1.1.2. As a temporary workaround, restrict access to the motordesk admin home() function to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9724

Affected Products

Motordesk