PT-2026-65738 · WordPress · Facturación Electrónica Costa Rica

·

CVE-2026-9720

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Facturación Electrónica Costa Rica versions prior to 2.0.3
Description The plugin is susceptible to Cross-Site Request Forgery (CSRF), a flaw where an attacker tricks a victim into performing actions they did not intend to do. This occurs due to missing or incorrect nonce validation within the (global scope, included by fvcr admin page html) function. Unauthenticated attackers can exploit this to modify plugin configurations via forged requests, provided they can induce a site administrator to click a malicious link. Affected settings include API tokens, access tokens, economic activity, Hacienda environment mode, invoice and ticket emission flags, exchange rate, and branch settings.
Recommendations Update the plugin to a version newer than 2.0.2.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9720

Affected Products

Facturación Electrónica Costa Rica