PatchSiren cyber security CVE debrief
CVE-2026-24574 Recorp CVE debrief
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Export WP Page to Static HTML/CSS WordPress plugin. The vulnerability affects versions from n/a through 6.0.0. CSRF vulnerabilities allow attackers to trick authenticated users into performing unintended actions on a web application without their knowledge. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N) indicates this is a network-accessible attack with low complexity, requiring no privileges but user interaction, resulting in high integrity impact with no confidentiality or availability impact. The vulnerability was published on 2026-05-25 and last modified on 2026-05-26. The weakness is categorized as CWE-352 (Cross-Site Request Forgery).
- Vendor
- Recorp
- Product
- Export WP Page to Static HTML/CSS
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-25
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-25
- Advisory updated
- 2026-07-24
Who should care
WordPress site administrators using the Export WP Page to Static HTML/CSS plugin; security teams managing WordPress installations; developers maintaining WordPress plugins with administrative functionality
Technical summary
The Export WP Page to Static HTML/CSS WordPress plugin contains a Cross-Site Request Forgery vulnerability in versions through 6.0.0. The plugin fails to properly validate or require nonces for state-changing requests, allowing attackers to forge requests that execute actions in the context of an authenticated administrator. The attack requires user interaction (e.g., clicking a malicious link) but can result in high integrity impact such as unauthorized configuration changes or data manipulation. The vulnerability is exploitable over the network with low attack complexity.
Defensive priority
medium
Recommended defensive actions
- Update Export WP Page to Static HTML/CSS WordPress plugin to a version newer than 6.0.0 when available
- Implement additional CSRF protections such as SameSite cookie attributes and custom request headers for administrative functions
- Review WordPress admin user sessions for unexpected actions around the plugin's export functionality
- Monitor for plugin security updates from the vendor
- Consider implementing Web Application Firewall (WAF) rules to detect and block suspicious cross-origin requests to plugin endpoints
Evidence notes
The vulnerability affects the Export WP Page to Static HTML/CSS WordPress plugin versions through 6.0.0. The source indicates this was reported by Patchstack ([email protected]). The NVD status is currently 'Deferred'. No known exploitation in the wild or ransomware campaign use has been identified.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-24574 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-24574
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-24574 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24574
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.