SR WP Minify HTML - Cross-Site Request Forgery to Settings Update vulnerability
mediumCross-Site Request Forgery to Settings Update vulnerability
- CVSS:
- 4.3
- Affected:
- up to 2.1
- Fix:
- No patched version reported
- Disclosed:
- Mar 23, 2026
plugin
2 known security issues reported for the Sr Wp Minify Html WordPress plugin. Most recent disclosed Mar 23, 2026.
Running Sr Wp Minify Html on your site? Check whether your installed version is affected.
Scan your site freeCross-Site Request Forgery to Settings Update vulnerability
The SR WP Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing nonce validation on the sr_minify_html_theme() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted th...
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free