PatchSiren cyber security CVE debrief
CVE-2026-8943 rchmura CVE debrief
Cross-Site Request Forgery (CSRF) vulnerability in GoStats for WordPress plugin versions up to and including 1.4. The gostats_manage() function lacks proper nonce validation, allowing unauthenticated attackers to modify plugin settings (gostats_siteid and gostats_server options) if an administrator can be tricked into clicking a malicious link.
- Vendor
- rchmura
- Product
- GoStats for WordPress
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-05-27
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-05-27
Who should care
WordPress site administrators using GoStats for WordPress plugin versions ≤1.4; security teams managing WordPress deployments; developers maintaining forked or customized versions of the plugin
Technical summary
The GoStats for WordPress plugin fails to implement WordPress nonce verification in its gostats_manage() function, a standard WordPress security mechanism for preventing CSRF attacks. Without nonce validation, state-changing requests can be forged and submitted on behalf of authenticated administrators. The vulnerability specifically exposes the gostats_siteid and gostats_server configuration options to unauthorized modification. Attack vector requires social engineering to induce administrator interaction.
Defensive priority
medium
Recommended defensive actions
- Update GoStats for WordPress plugin to version 1.5 or later when available
- Implement additional CSRF protection on administrative endpoints
- Review plugin settings for unauthorized modifications if running affected versions
- Consider disabling the plugin until a patch is available
- Deploy web application firewall rules to detect and block suspicious POST requests to plugin management endpoints
Evidence notes
Vulnerability confirmed via Wordfence security advisory. Source code references indicate missing nonce checks at lines 26-27 of GoStats.php. CVSS 3.1 score of 4.3 (Medium) reflects network attack vector with user interaction required.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8943 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8943
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8943 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8943
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/gostats-for-wordpress/trunk/GoStats.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/gostats-for-wordpress/trunk/GoStats.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.