CVE-2026-3191: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-3191 is a Cross-Site Request Forgery (CSRF) vulnerability in the Minify HTML plugin for WordPress, affecting all versions up to and including 2.1.12. The flaw exists in the minify_html_menu_options function due to missing or incorrect nonce validation, allowing unauthenticated attackers to modify plugin settings by tricking an administrator into clicking a malicious link. It was published on March 31, 2026, with a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Wordfence).

Technical details

The root cause is CWE-352 (Cross-Site Request Forgery), specifically the absence of proper nonce validation in the minify_html_menu_options function (visible at line 139 of minify-html.php in version 2.1.12). Because WordPress nonces are not verified before processing settings updates, a forged HTTP request submitted in the context of an authenticated administrator session can successfully alter plugin configuration. Exploitation requires social engineering — the attacker must trick a logged-in site administrator into visiting a malicious page or clicking a crafted link that submits the forged request (GitHub Advisory, WordPress Trac).

Impact

Successful exploitation allows an unauthenticated attacker to modify the Minify HTML plugin's configuration on the affected WordPress site, resulting in low integrity and low availability impacts with no confidentiality exposure. Depending on the plugin settings altered, an attacker could disrupt HTML minification behavior, potentially breaking site functionality or injecting undesired configuration changes. The scope is limited to the affected WordPress installation and does not directly enable remote code execution or data exfiltration (GitHub Advisory, Wordfence).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (1st percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (GitHub Advisory, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Minify HTML plugin (version ≤ 2.1.12) by inspecting page source for plugin-specific HTML comments or using web fingerprinting tools.
  2. Craft forged request: Construct an HTTP POST request targeting the WordPress admin settings endpoint for the Minify HTML plugin (e.g., wp-admin/options-general.php?page=minify-html) with desired malicious parameter values and no valid nonce.
  3. Deliver payload: Embed the forged request in a malicious web page (e.g., as a hidden HTML form with auto-submit JavaScript) or disguise it as a link in a phishing email targeting the site administrator.
  4. Trigger execution: When the authenticated administrator visits the attacker-controlled page or clicks the link, the browser automatically submits the forged request with the administrator's session cookies, causing the plugin settings to be updated without the administrator's knowledge (GitHub Advisory, WordPress Trac).

Indicators of compromise

  • Logs: Unexpected POST requests to wp-admin/options-general.php or similar admin settings pages from unusual referrer URLs or external origins in WordPress access logs.
  • File System: Changes to plugin configuration stored in the WordPress database (wp_options table) for the minify_html option key at unexpected times.
  • Logs: WordPress admin action logs (if an audit plugin is installed) showing settings changes to the Minify HTML plugin without a corresponding administrator login session from a known IP.

Mitigation and workarounds

Administrators should update the Minify HTML plugin to a version newer than 2.1.12, which includes the fix adding proper nonce validation to the minify_html_menu_options function. The patch is available via the WordPress plugin repository changeset. As a general defense-in-depth measure, administrators should be cautious about clicking links from untrusted sources while logged into the WordPress admin panel, and consider implementing Content Security Policy (CSP) headers to reduce CSRF risk (WordPress Trac Changeset, Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management