CVE-2026-2023: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2023 is a Cross-Site Request Forgery (CSRF) vulnerability in the WP Plugin Info Card plugin for WordPress, affecting all versions up to and including 6.2.0. The flaw allows unauthenticated attackers to create or modify custom plugin entries by tricking a site administrator into performing an action such as clicking a malicious link. It was published on February 18, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly).

Technical details

The root cause is missing nonce validation in the ajax_save_custom_plugin() function (CWE-352: Cross-Site Request Forgery). Specifically, the nonce check is intentionally disabled by prefixing the conditional with false &&, rendering the wp_verify_nonce() call unreachable: if ( false && ! wp_verify_nonce( $nonce, 'wppic-save-custom-plugin' ) ). This means any forged POST request to the AJAX handler can create or update custom plugin entries in the WordPress database without authentication, as long as a logged-in administrator's browser session is used. The vulnerable code is visible in the plugin's source at php/Admin/Init.php around line 390 (GitHub Source).

Impact

Successful exploitation allows an unauthenticated attacker to create or modify custom plugin entries stored in the WordPress database, resulting in a low integrity impact with no confidentiality or availability impact. While the direct damage is limited, manipulated plugin entries could be used to display misleading information to site visitors or administrators, potentially facilitating further social engineering attacks. The vulnerability does not allow remote code execution or data exfiltration on its own (Feedly).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering — the attacker must trick a logged-in administrator into visiting a malicious page or clicking a crafted link (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running WP Plugin Info Card version 6.2.0 or earlier using tools like WPScan or by inspecting publicly accessible plugin metadata.
  2. Craft malicious request: Prepare a forged HTML form or JavaScript snippet that submits a POST request to the target site's WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with action=wppic_save_custom_plugin and attacker-controlled wppicFormData parameters (e.g., plugin name, slug, content).
  3. Social engineering: Deliver the malicious page or link to a site administrator via phishing email, comment, or other channel, causing their authenticated browser session to submit the forged request.
  4. Achieve objective: Upon the administrator loading the attacker's page, the forged AJAX request is sent with the administrator's session cookies, bypassing the disabled nonce check and creating or modifying a custom plugin entry in the WordPress database (GitHub Source).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected POST requests to /wp-admin/admin-ajax.php with action=wppic_save_custom_plugin from unusual IP addresses or referrers not matching the site's admin panel.
  • Database: Unexpected or unfamiliar entries in the wppic_custom_plugins custom post type within the WordPress wp_posts table, particularly those created at unusual times or with suspicious content.
  • File System: No direct file system artifacts expected, as the attack operates via database manipulation through the AJAX endpoint.

Mitigation and workarounds

Site administrators should update the WP Plugin Info Card plugin to a version beyond 6.2.0 that includes a proper nonce validation fix (i.e., where the false && prefix has been removed from the nonce check in ajax_save_custom_plugin()). Until a patched version is confirmed available, administrators can temporarily deactivate the plugin to eliminate the attack surface. Additionally, general WordPress hardening practices — such as limiting administrator account exposure and using a web application firewall (WAF) to block suspicious AJAX requests — can reduce risk (Feedly).

Community reactions

Coverage of this vulnerability has been limited to automated vulnerability database aggregators and security feed services. A brief technical write-up was published at infinitsec.net shortly after disclosure. No notable researcher commentary or significant community discussion has been identified beyond standard CVE tracking (Feedly).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management