
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2023 is a Cross-Site Request Forgery (CSRF) vulnerability in the WP Plugin Info Card plugin for WordPress, affecting all versions up to and including 6.2.0. The flaw allows unauthenticated attackers to create or modify custom plugin entries by tricking a site administrator into performing an action such as clicking a malicious link. It was published on February 18, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly).
The root cause is missing nonce validation in the ajax_save_custom_plugin() function (CWE-352: Cross-Site Request Forgery). Specifically, the nonce check is intentionally disabled by prefixing the conditional with false &&, rendering the wp_verify_nonce() call unreachable: if ( false && ! wp_verify_nonce( $nonce, 'wppic-save-custom-plugin' ) ). This means any forged POST request to the AJAX handler can create or update custom plugin entries in the WordPress database without authentication, as long as a logged-in administrator's browser session is used. The vulnerable code is visible in the plugin's source at php/Admin/Init.php around line 390 (GitHub Source).
Successful exploitation allows an unauthenticated attacker to create or modify custom plugin entries stored in the WordPress database, resulting in a low integrity impact with no confidentiality or availability impact. While the direct damage is limited, manipulated plugin entries could be used to display misleading information to site visitors or administrators, potentially facilitating further social engineering attacks. The vulnerability does not allow remote code execution or data exfiltration on its own (Feedly).
No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering — the attacker must trick a logged-in administrator into visiting a malicious page or clicking a crafted link (Feedly).
/wp-admin/admin-ajax.php) with action=wppic_save_custom_plugin and attacker-controlled wppicFormData parameters (e.g., plugin name, slug, content)./wp-admin/admin-ajax.php with action=wppic_save_custom_plugin from unusual IP addresses or referrers not matching the site's admin panel.wppic_custom_plugins custom post type within the WordPress wp_posts table, particularly those created at unusual times or with suspicious content.Site administrators should update the WP Plugin Info Card plugin to a version beyond 6.2.0 that includes a proper nonce validation fix (i.e., where the false && prefix has been removed from the nonce check in ajax_save_custom_plugin()). Until a patched version is confirmed available, administrators can temporarily deactivate the plugin to eliminate the attack surface. Additionally, general WordPress hardening practices — such as limiting administrator account exposure and using a web application firewall (WAF) to block suspicious AJAX requests — can reduce risk (Feedly).
Coverage of this vulnerability has been limited to automated vulnerability database aggregators and security feed services. A brief technical write-up was published at infinitsec.net shortly after disclosure. No notable researcher commentary or significant community discussion has been identified beyond standard CVE tracking (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."