PT-2026-84636 · WordPress · Jetstylemanager For Gutenberg

CVE-2026-81432

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions JetStyleManager for Gutenberg WordPress versions prior to 1.3.9
Description Certain AJAX actions lack Cross-Site Request Forgery (CSRF) protection. This allows an attacker to trick a logged-in user with the edit posts capability, such as a Contributor or higher, into deleting or modifying custom widget skins by inducing them to perform an action like clicking a crafted link.
Recommendations Update JetStyleManager for Gutenberg WordPress to version 1.3.9 or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81432

Affected Products

Jetstylemanager For Gutenberg