What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in jprintf CNZZ&51LA for WordPress cnzz51la-for-wordpress allows Cross Site Request Forgery.This issue affects CNZZ&51LA for WordPress: from n/a through <= 1.0.1.
Explanation of Vulnerability in Simple Terms
02Summary
The CNZZ&51LA WordPress plugin through version 1.0.1 contains a cross-site request forgery (CSRF) vulnerability. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the site without their knowledge. The vulnerability affects confidentiality, integrity, and availability of the site.
What an attacker can do
03Attacker Capabilities
Trick a logged-in admin into performing unwanted actions on the site via a malicious webpage.
Potential impact on your site
04Site Impact
An attacker can modify site settings, create accounts, or alter content if an admin visits a compromised page.
Conditions required to exploit
05Prerequisites
Admin must visit a malicious webpage while logged into WordPress.
Key dates
06Disclosure timeline
January 16, 2025
CVE published
May 11, 2026
Record updated