CVE-2026-1073: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1073 is a Cross-Site Request Forgery (CSRF) vulnerability in the Purchase Button For Affiliate Link WordPress plugin, developed by Themepul. It affects all versions up to and including 1.0.2, and allows unauthenticated attackers to modify plugin settings by tricking a logged-in administrator into clicking a malicious link. The vulnerability was published on March 7, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is missing nonce validation on the settings page form handler located in inc/purchase-btn-options-page.php (CWE-352: Cross-Site Request Forgery). Because the plugin does not verify a WordPress nonce (anti-CSRF token) when processing settings form submissions, any forged HTTP request that originates from an authenticated administrator's browser will be accepted and processed. An attacker crafts a malicious HTML page or link containing a form that submits to the plugin's settings handler, then socially engineers a site administrator into visiting or clicking it. No authentication or special privileges are required on the attacker's side — only the victim's authenticated session is needed (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an unauthenticated attacker to modify the Purchase Button For Affiliate Link plugin's settings on a victim WordPress site, potentially redirecting affiliate purchase buttons to attacker-controlled URLs or altering other plugin configurations. The integrity impact is limited to plugin settings (CVSS integrity impact: Low), with no direct confidentiality or availability impact. However, manipulation of affiliate links could result in financial loss for the site owner or exposure of site visitors to malicious destinations (Wordfence).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2026-1073. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering of a site administrator, which raises the practical bar for attackers (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Purchase Button For Affiliate Link plugin (version ≤ 1.0.2) via passive enumeration (e.g., searching for plugin-specific assets in page source or using tools like WPScan).
  2. Craft malicious request: Create an HTML page or email containing a hidden auto-submitting form that targets the plugin's settings handler endpoint (the form action pointing to the WordPress admin settings page for the plugin, e.g., wp-admin/options-general.php?page=purchase-button).
  3. Inject desired settings: Populate the form fields with attacker-controlled values (e.g., a malicious affiliate URL to replace the legitimate one), exploiting the absence of nonce validation in inc/purchase-btn-options-page.php.
  4. Social engineering: Deliver the malicious link or page to a site administrator via phishing email, forum post, or comment, and trick them into clicking it while authenticated to their WordPress dashboard.
  5. Settings modified: The administrator's browser submits the forged form, and the plugin processes it without CSRF verification, updating the plugin settings to the attacker's chosen values (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress admin audit logs or server access logs showing unexpected POST requests to the plugin settings page (e.g., wp-admin/options-general.php?page=purchase-button) from unusual referrers or at unusual times.
  • File System / Database: Unexpected changes to plugin settings stored in the WordPress wp_options table, particularly fields associated with the Purchase Button For Affiliate Link plugin (e.g., affiliate link URLs changed to unknown domains).
  • Network: Outbound links or redirects from the WordPress site pointing to unfamiliar or suspicious affiliate/external URLs that were not configured by the site owner.

Mitigation and workarounds

Site administrators should update the Purchase Button For Affiliate Link plugin to a version beyond 1.0.2 if a patched release is available from the plugin developer (Themepul). If no patched version is yet available, administrators should consider deactivating or removing the plugin until a fix is released. As a general hardening measure, restrict access to the WordPress admin dashboard to trusted IP addresses and ensure administrators are cautious about clicking unsolicited links while logged in (Wordfence, WordPress Trac).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management