Moderate Selected Posts WordPress Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Moderate Selected Posts WordPress plugin, affecting all versions through 1.4. The issue arises from a lack of nonce verification in the msp_admin_page() function, allowing unauthenticated attackers to alter plugin settings. Exploitation requires tricking a site administrator into clicking a link that initiates the forged request.

Impact

Exploitation of this vulnerability allows for Cross-Site Request Forgery, enabling unauthorized changes to plugin settings.

Reproduction

To reproduce this vulnerability, an attacker must create a forged request that exploits the missing nonce verification in the msp_admin_page() function. This can be done by tricking a site administrator into clicking a link that activates the forged request, thereby bypassing the intended security measures.

Remediation

No known patch is available for this vulnerability. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.

Added: Jan 24, 2026, 9:32 AM
Updated: Jan 24, 2026, 9:32 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.2
remediation
0.0
relevance
2.3
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.