PT-2026-95701 · WordPress · Cotonti

CVE-2026-93870

·

Published

2026-09-18

·

Updated

2026-09-22

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Cotonti versions prior to 1.0.1
Description The ratings plugin AJAX handler fails to validate anti-CSRF tokens, which are unique tokens used to prevent Cross-Site Request Forgery (CSRF)—an attack that forces an authenticated user to execute unwanted actions. This allows attackers to forge ratings on behalf of authenticated users by crafting malicious pages that automatically submit POST requests to modify stored rating data when visited by logged-in users.
Recommendations Update to a version newer than 1.0.0.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93870

Affected Products

Cotonti