PT-2026-95701 · WordPress · Cotonti
CVE-2026-93870
·
Published
2026-09-18
·
Updated
2026-09-22
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Cotonti versions prior to 1.0.1
Description
The ratings plugin AJAX handler fails to validate anti-CSRF tokens, which are unique tokens used to prevent Cross-Site Request Forgery (CSRF)—an attack that forces an authenticated user to execute unwanted actions. This allows attackers to forge ratings on behalf of authenticated users by crafting malicious pages that automatically submit POST requests to modify stored rating data when visited by logged-in users.
Recommendations
Update to a version newer than 1.0.0.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cotonti