
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3191 is a Cross-Site Request Forgery (CSRF) vulnerability in the Minify HTML plugin for WordPress, affecting all versions up to and including 2.1.12. The flaw exists in the minify_html_menu_options function due to missing or incorrect nonce validation, allowing unauthenticated attackers to modify plugin settings by tricking an administrator into clicking a malicious link. It was published on March 31, 2026, with a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Wordfence).
The root cause is CWE-352 (Cross-Site Request Forgery), specifically the absence of proper nonce validation in the minify_html_menu_options function (visible at line 139 of minify-html.php in version 2.1.12). Because WordPress nonces are not verified before processing settings updates, a forged HTTP request submitted in the context of an authenticated administrator session can successfully alter plugin configuration. Exploitation requires social engineering — the attacker must trick a logged-in site administrator into visiting a malicious page or clicking a crafted link that submits the forged request (GitHub Advisory, WordPress Trac).
Successful exploitation allows an unauthenticated attacker to modify the Minify HTML plugin's configuration on the affected WordPress site, resulting in low integrity and low availability impacts with no confidentiality exposure. Depending on the plugin settings altered, an attacker could disrupt HTML minification behavior, potentially breaking site functionality or injecting undesired configuration changes. The scope is limited to the affected WordPress installation and does not directly enable remote code execution or data exfiltration (GitHub Advisory, Wordfence).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (1st percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (GitHub Advisory, Wordfence).
wp-admin/options-general.php?page=minify-html) with desired malicious parameter values and no valid nonce.wp-admin/options-general.php or similar admin settings pages from unusual referrer URLs or external origins in WordPress access logs.wp_options table) for the minify_html option key at unexpected times.Administrators should update the Minify HTML plugin to a version newer than 2.1.12, which includes the fix adding proper nonce validation to the minify_html_menu_options function. The patch is available via the WordPress plugin repository changeset. As a general defense-in-depth measure, administrators should be cautious about clicking links from untrusted sources while logged into the WordPress admin panel, and consider implementing Content Security Policy (CSP) headers to reduce CSRF risk (WordPress Trac Changeset, Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."