LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-3772 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: May 1, 2026

WP Editor WordPress Plugin - Cross-Site Request Forgery

Published: May 1, 2026Updated: May 1, 2026Remote Exploitable

Overview

WP Editor plugin for WordPress <= 1.2.9.2 contains a cross-site request forgery caused by missing nonce verification in 'add_plugins_page' and 'add_themes_page' functions, letting unauthenticated attackers overwrite plugin and theme PHP files via forged requests, exploit requires site administrator interaction.

Severity & Score

Severity: High
CVSS Score: 8.8

Impact

Attackers can overwrite plugin and theme PHP files with malicious code, leading to remote code execution and full site compromise.

Mitigation

Update to the latest version beyond 1.2.9.2.

Details

CVE ID
CVE-2026-3772
Severity
High
CVSS Score
8.8
Type
cross_site_request_forgery
Status
new

CWE

  • CWE-352

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H