
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1073 is a Cross-Site Request Forgery (CSRF) vulnerability in the Purchase Button For Affiliate Link WordPress plugin, developed by Themepul. It affects all versions up to and including 1.0.2, and allows unauthenticated attackers to modify plugin settings by tricking a logged-in administrator into clicking a malicious link. The vulnerability was published on March 7, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is missing nonce validation on the settings page form handler located in inc/purchase-btn-options-page.php (CWE-352: Cross-Site Request Forgery). Because the plugin does not verify a WordPress nonce (anti-CSRF token) when processing settings form submissions, any forged HTTP request that originates from an authenticated administrator's browser will be accepted and processed. An attacker crafts a malicious HTML page or link containing a form that submits to the plugin's settings handler, then socially engineers a site administrator into visiting or clicking it. No authentication or special privileges are required on the attacker's side — only the victim's authenticated session is needed (Wordfence, WordPress Trac).
Successful exploitation allows an unauthenticated attacker to modify the Purchase Button For Affiliate Link plugin's settings on a victim WordPress site, potentially redirecting affiliate purchase buttons to attacker-controlled URLs or altering other plugin configurations. The integrity impact is limited to plugin settings (CVSS integrity impact: Low), with no direct confidentiality or availability impact. However, manipulation of affiliate links could result in financial loss for the site owner or exposure of site visitors to malicious destinations (Wordfence).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2026-1073. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering of a site administrator, which raises the practical bar for attackers (Wordfence, Red Hat CVE).
wp-admin/options-general.php?page=purchase-button).inc/purchase-btn-options-page.php.wp-admin/options-general.php?page=purchase-button) from unusual referrers or at unusual times.wp_options table, particularly fields associated with the Purchase Button For Affiliate Link plugin (e.g., affiliate link URLs changed to unknown domains).Site administrators should update the Purchase Button For Affiliate Link plugin to a version beyond 1.0.2 if a patched release is available from the plugin developer (Themepul). If no patched version is yet available, administrators should consider deactivating or removing the plugin until a fix is released. As a general hardening measure, restrict access to the WordPress admin dashboard to trusted IP addresses and ensure administrators are cautious about clicking unsolicited links while logged in (Wordfence, WordPress Trac).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."