CVE-2026-96838: WordPress Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification plugin <= 2.3.1 - Cross Site Request Forgery (CSRF) vulnerability
Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification <= 2.3.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verificationto a version that resolves this vulnerability.Fixed in 2.3.2
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker does not need to authenticate to the affected plugin, but exploitation requires a user to interact with a crafted request. The supplied data does not identify which user role must be targeted or which action can be performed.
Which installations are known to be affected?
Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification versions 2.3.1 and earlier are identified as affected. The provided information does not state whether a particular plugin configuration is required.
How severe is the reported impact?
The vulnerability is rated High with a CVSS score of 8.8. The supplied vector indicates network reachability, low attack complexity, no attacker privileges, required user interaction, and high confidentiality, integrity, and availability impact.