LEAV Last Email Address Validator WordPress Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the LEAV Last Email Address Validator plugin for WordPress, affecting versions through 1.7.1. The vulnerability arises from inadequate nonce validation in the 'display_settings_page' function, allowing unauthenticated attackers to alter plugin settings by sending a forged request, provided they can deceive a site administrator into clicking a link.

Impact

Exploitation of this vulnerability allows for unauthorized modification of plugin settings by an attacker, potentially leading to incorrect email validation and increased spam.

Added: Jan 16, 2026, 7:22 AM
Updated: Jan 16, 2026, 7:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.0
remediation
0.0
relevance
2.0
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.