Minify HTML - Cross-Site Request Forgery to Plugin Settings Update vulnerability
mediumCross-Site Request Forgery to Plugin Settings Update vulnerability
- CVSS:
- 4.3
- Affected:
- up to 2.1.12
- Fixed in:
- 2.1.13
- Disclosed:
- Mar 31, 2026
plugin
4 known security issues reported for the Minify Html Markup WordPress plugin. Most recent disclosed Mar 31, 2026.
Running Minify Html Markup on your site? Check whether your installed version is affected.
Scan your site freeCross-Site Request Forgery to Plugin Settings Update vulnerability
The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing or incorrect nonce validation on the 'minify_html_menu_options' function. This makes it possible for unauthenticated attackers to update plugin settings via a forged requ...
The Minify HTML plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 2.1.10. This is due to processing user-supplied input as a regular expression. This makes it possible for unauthenticated attackers to create comments that can cause catastrophic bac...
The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.7. This is due to missing or incorrect nonce validation on the minify_html_menu_options function. This makes it possible for unauthenticated attackers to modify the plugin's settings granted they can t...
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free