WP Quick Contact Us WordPress Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP Quick Contact Us plugin for WordPress, affecting all versions through 1.0. The vulnerability arises from a lack of nonce validation in the settings update process, allowing unauthenticated attackers to manipulate the plugin's settings by tricking a site administrator into clicking a link or performing a similar action.

Impact

Exploitation of this vulnerability allows for unauthorized modification of the plugin's settings, which could lead to unauthorized actions being performed on behalf of the user.

Reproduction

To reproduce this vulnerability, an attacker must craft a forged request that exploits the missing nonce validation. This can be done by creating a link that, when clicked by an administrator, sends a request to update the plugin's settings without the required nonce. The absence of validation allows the settings to be changed without the administrator's knowledge or consent.

Added: Feb 14, 2026, 8:22 AM
Updated: Feb 14, 2026, 8:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.2
remediation
0.0
relevance
3.0
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.