WordPress Plugin Vulnerabilities

JetStyleManager < 1.3.9 - Skin Deletion and Modification via CSRF

Description

The plugin does not have CSRF protection on some of its AJAX actions, allowing attackers to make a logged-in user with the edit_posts capability (Contributor and above) delete or modify custom widget skins via a crafted request, provided they can trick the user into performing an action such as clicking a link.

Proof of Concept

Affects Plugins

Fixed in 1.3.9

References

Classification

Miscellaneous

Original Researcher
Huynh Kien Minh
Submitter
Huynh Kien Minh
Verified
Yes

Timeline

Publicly Published
2026-08-31 (about 2 days ago)
Added
2026-08-31 (about 1 day ago)
Last Updated
2026-08-31 (about 1 day ago)

Other