
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22483 is a Cross-Site Request Forgery (CSRF) vulnerability in the teachPress WordPress plugin developed by winkm89. It affects all versions of teachPress through 9.0.12 and was disclosed on January 22, 2026, with the CVE received from Patchstack. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium), as assigned by Patchstack (NVD, Patchstack).
The vulnerability is classified under CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to properly validate that state-changing requests originate from legitimate, authenticated sessions. An attacker can craft a malicious web page or link that, when visited by an authenticated WordPress user (such as an administrator), triggers unauthorized actions within the teachPress plugin on their behalf. No privileges are required by the attacker, but user interaction is necessary — the victim must be tricked into visiting a malicious URL or page while authenticated (NVD, Patchstack).
Successful exploitation can result in unauthorized modifications to plugin data and limited availability impact, as reflected in the CVSS scoring (integrity: Low, availability: Low, confidentiality: None). An attacker could manipulate academic publication records, student data, or plugin settings managed by teachPress without the victim's knowledge. The scope is limited to the affected WordPress instance and does not directly expose sensitive data, but could disrupt the integrity of academic content managed by the plugin (NVD).
There is no known public proof-of-concept exploit code or evidence of active in-the-wild exploitation for CVE-2026-22483 at this time. The EPSS score is extremely low at 0.000080, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (NVD).
<img>, <form>, or JavaScript auto-submit technique that triggers the request automatically when loaded.Referer headers pointing to external sites.Users should update the teachPress plugin to a version beyond 9.0.12 that includes CSRF token validation fixes, once a patched release is made available by the developer (winkm89). In the interim, administrators should restrict access to WordPress admin areas using IP allowlisting or additional authentication layers, and educate privileged users to avoid clicking unsolicited links while logged into WordPress. Monitoring WordPress admin activity logs for unexpected changes to teachPress data is also recommended (NVD, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."