WordPress Linear Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Linear plugin for WordPress, affecting all versions up to and including 2.8.1. The issue arises from inadequate nonce validation on the 'linear-debug' page, allowing unauthenticated attackers to reset the plugin's cache by sending a forged request, provided they can persuade a site administrator to click a link or perform a similar action.

Impact

Exploitation of this vulnerability allows for Cross-Site Request Forgery, enabling attackers to perform actions on behalf of users without their consent, such as resetting the plugin's cache.

Reproduction

To reproduce this vulnerability, an attacker must send a forged request to a WordPress site with the Linear plugin installed, targeting the 'linear-debug' page. The request should include the necessary nonces to bypass security checks. This can be done by tricking an administrator into clicking a link that activates the forged request, effectively resetting the plugin's cache.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
7.6
remediation
0.0
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.