CVE-2026-1392Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The SR WP Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing nonce validation on the sr_minify_html_theme() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-21: 2Patch / Workaround · 2026-03-21: 1Technical Details · 2026-03-21: 203-21
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Fernando Karl@fernandokarl
    Patch

    🚨 Attention WordPress admins! The SR WP Minify HTML plugin (versions ≤ 2.1) has a serious CSRF vulnerability allowing attackers to alter configurations. Update now or disable the plugin! Protect your site! 🔒 🔗: https://www.tenable.com/cve/CVE-2026-1392 #Cybersecurity #WordPress #CSRF

    Post summary

    The notice warns WordPress admins that SR WP Minify HTML plugin versions ≤ 2.1 have a CSRF flaw allowing configuration changes and urges them to update or disable the plugin.

    0000030
    259 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1392 The SR WP Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing nonce validatio… https://www.cve.org/CVERecord?id=CVE-2026-1392

    Post summary

    The SR WP Minify HTML plugin is disclosed as vulnerable to CSRF due to missing nonce validation, with no PoC, exploit, or patch mentioned.

    0000067
    56.8K followersView on X

Explore more