CVE 4.3 MEDIUM

Friendly Functions for Welcart <= 1.2.5 - Cross-Site Request Forgery to Settings Update_CVE-2026-1208

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the settings page. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Basic Information

ID CVE-2026-1208
Source Wordfence
Published Jan 24, 2026 at 09:08

Affected Product

Vendor mainichiweb
Product Friendly Functions for Welcart
Version *
Affected Versions mainichiweb Friendly Functions for Welcart *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.