Description
The ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to missing or incorrect nonce validation on the ark_rp_options_page function. This makes it possible for unauthenticated attackers to modify the plugin's configuration settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published: 2025-12-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Request Forgery allowing unauthorized modification of plugin configuration
Action: Apply Patch
AI Analysis

Impact

The ARK Related Posts WordPress plugin contains a CSRF weakness due to missing or incorrect nonce validation in the ark_rp_options_page function. As a result, an unauthenticated attacker can trick a site administrator into sending a forged request that updates plugin settings. While the vulnerability does not expose code execution, it permits an attacker to alter configuration values that could affect the site’s content display or functionality, compromising the integrity of the site’s appearance and user experience.

Affected Systems

Vendors: alexkar—ARK Related Posts. Affected plugin versions are 2.19 and all earlier releases. No other versions are reported to be impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at the current time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to entice a legitimate administrator to execute a link or form that submits a POST request to the settings page, exploiting the missing nonce to bypass authentication checks. Consequently, the primary risk is the unauthorized configuration of the plugin by a non‑privileged actor.

Generated by OpenCVE AI on April 21, 2026 at 17:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ARK Related Posts plugin to a version newer than 2.19 that restores nonce validation in the settings page.
  • Restrict access to the plugin's settings area to administrators only, ensuring no other roles can reach the vulnerable endpoint.
  • Configure a web application firewall or equivalent rule to flag requests to ark_rp_options_page that lack a valid nonce, blocking or alerting on such traffic.

Generated by OpenCVE AI on April 21, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
References

Fri, 05 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 05 Dec 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description The ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to missing or incorrect nonce validation on the ark_rp_options_page function. This makes it possible for unauthenticated attackers to modify the plugin's configuration settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Title ARK Related Posts <= 2.19 - Cross-Site Request Forgery to Settings Update
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:03:13.105Z

Reserved: 2025-11-25T19:50:36.998Z

Link: CVE-2025-13684

cve-icon Vulnrichment

Updated: 2025-12-05T12:58:55.208Z

cve-icon NVD

Status : Deferred

Published: 2025-12-05T08:15:47.883

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-13684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T17:45:16Z

Weaknesses