ARK Related Posts <= 2.19 - Cross-Site Request Forgery to Settings Update
mediumThe ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to missing or incorrect nonce validation on the ark_rp_options_page function. This makes it possible for unauthenticated attackers to modify the plugin's configuration settings via a forged request grante...
- CVSS:
- 4.3
- Affected:
- up to 2.19
- Fixed in:
- 2.20
- Disclosed:
- Dec 4, 2025