Description
The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect nonce validation on the googlePlusOneAdmin function. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the plusone-lang, plusone-callback, and plusone-url options stored in the database via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published: 2026-06-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from missing or incorrect nonce validation in the Google Plus One Bottom plugin for WordPress, enabling attackers to perform a cross‑site request forgery that updates the plugin’s settings. An unauthenticated user can trick an administrator into visiting a crafted URL or clicking a link, causing the server to store new values for options such as plusone-lang, plusone-callback, and plusone-url. The impact is primarily a compromise of integrity, as the attacker can redirect users or alter the Google+ integration without accessing the site’s data directly.

Affected Systems

WordPress sites that have the Google Plus One Bottom plugin installed at version 0.0.2 or earlier. Any administrator who remains logged in while visiting a forged request could be impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, while no EPSS score is available and the vulnerability is not listed in CISA’s KEV table, suggesting there is no known large‑scale exploitation. The attack vector is limited to social‑engineering scenarios where an attacker can lure an administrator to a malicious link; no bypass of authentication is required, but the victim must be an admin and actively logged in. Consequently, the risk is present but relies on a targeted attack surface and does not affect all site users automatically.

Generated by OpenCVE AI on June 2, 2026 at 09:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Plus One Bottom to the latest available version to ensure proper nonce validation is in place.
  • If an update is unavailable, consider temporarily disabling the plugin or removing it entirely to eliminate the attack surface.
  • Enhance administrator security by enforcing strong passwords, IP restrictions, and two‑factor authentication to reduce the likelihood that an admin will unknowingly trigger a CSRF request.

Generated by OpenCVE AI on June 2, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 04 Jun 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Ddd2500
Ddd2500 google Plus One Bottom
Wordpress
Wordpress wordpress
Vendors & Products Ddd2500
Ddd2500 google Plus One Bottom
Wordpress
Wordpress wordpress

Tue, 02 Jun 2026 08:30:00 +0000

Type Values Removed Values Added
Description The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect nonce validation on the googlePlusOneAdmin function. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the plusone-lang, plusone-callback, and plusone-url options stored in the database via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Title Google Plus One Bottom <= 0.0.2 - Cross-Site Request Forgery to Plugin Settings Update via Settings Page
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Ddd2500 Google Plus One Bottom
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-06-02T10:46:10.769Z

Reserved: 2026-05-27T16:09:47.148Z

Link: CVE-2026-9723

cve-icon Vulnrichment

Updated: 2026-06-02T10:46:06.245Z

cve-icon NVD

Status : Deferred

Published: 2026-06-02T09:16:17.437

Modified: 2026-06-02T13:03:31.153

Link: CVE-2026-9723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T20:51:59Z

Weaknesses