CVE-2026-8174: Cross-site Request Forgery
Published May 26, 2026
·Updated
Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF).
This issue affects Zoho Mail wordpress plugin versions before 1.6.2.
Affected Software
1 affected component
Zoho Zoho Mail WordPress plugin<1.6.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoho Mail wordpress pluginto a version that resolves this vulnerability.Fixed in 1.6.2
Event History
May 26, 2026
CVE Published
via MITRE·11:04 AM
Data Sourced
via MITRE·11:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-8174?
CVE-2026-8174 has a medium severity rating of 5.7.
2
How do I fix CVE-2026-8174?
To fix CVE-2026-8174, update the Zoho Mail WordPress plugin to version 1.6.2 or later.
3
What type of vulnerability is CVE-2026-8174?
CVE-2026-8174 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
Which versions of the Zoho Mail WordPress plugin are affected by CVE-2026-8174?
CVE-2026-8174 affects versions of the Zoho Mail WordPress plugin prior to 1.6.2.
5
What impact does CVE-2026-8174 have on users?
CVE-2026-8174 can allow attackers to perform unauthorized actions on behalf of authenticated users.