Description
The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's Knowledge Graph settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published: 2026-03-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Settings Change
Action: Apply Patch
AI Analysis

Impact

The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress contains a Cross‑Site Request Forgery vulnerability caused by the omission of nonce validation in its settings update routine. Because the plugin accepts options changes without verifying the request source, an unauthenticated attacker can craft a forged request that an administrator will unknowingly submit, allowing the attacker to modify the Knowledge Graph settings. Such a configuration change could lead to incorrect metadata being published or even injection of malicious links, compromising the integrity of published content.

Affected Systems

Plugins deployed on WordPress sites that use omarnas’ Add Google Social Profiles to Knowledge Graph Box, version 1.0 or earlier. Any installation of the plugin with those versions is affected while an administrator has editor or admin privileges and can be tricked into clicking a malicious link.

Risk and Exploitability

The CVSS base score for this issue is 4.3, indicating moderate risk. EPSS information is not published and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to target a site administrator and socially engineer a click on a crafted link, which limits the scope to sites with the vulnerable plugin installed. While the attack vector is user interaction, the lack of nonce checks means any forged request can be accepted, making the exploitation straightforward once a victim is lured. The overall risk is moderate but should be mitigated promptly on affected installations.

Generated by OpenCVE AI on March 21, 2026 at 06:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Add Google Social Profiles to Knowledge Graph Box plugin to the latest version, ensuring that nonce validation is in place.
  • If a new version is not yet available, disable or remove the plugin from the WordPress installation to eliminate the risk.
  • Apply timely security updates to WordPress core and other plugins to reduce the attack surface.
  • Restrict administrator accounts to trusted users, enforce strong passwords, and apply the principle of least privilege.
  • If possible, implement a web application firewall or CSRF protection plugin to block forged requests from reaching the plugin settings endpoint.

Generated by OpenCVE AI on March 21, 2026 at 06:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Omarnas
Omarnas add Google Social Profiles To Knowledge Graph Box
Wordpress
Wordpress wordpress
Vendors & Products Omarnas
Omarnas add Google Social Profiles To Knowledge Graph Box
Wordpress
Wordpress wordpress

Sat, 21 Mar 2026 05:30:00 +0000

Type Values Removed Values Added
Description The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's Knowledge Graph settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Title Add Google Social Profiles to Knowledge Graph Box <= 1.0 - Cross-Site Request Forgery to Settings Update
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Omarnas Add Google Social Profiles To Knowledge Graph Box
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:37:48.473Z

Reserved: 2026-01-23T20:59:09.378Z

Link: CVE-2026-1393

cve-icon Vulnrichment

Updated: 2026-03-23T18:10:58.222Z

cve-icon NVD

Status : Deferred

Published: 2026-03-21T04:16:53.380

Modified: 2026-04-22T21:32:08.360

Link: CVE-2026-1393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:42:33Z

Weaknesses