๐Ÿ” CVE Alert

CVE-2026-4141

MEDIUM 4.3

Quran Translations <= 1.7 - Cross-Site Request Forgery to Playlist Settings Form

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The Quran Translations plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing nonce validation in the quran_playlist_options() function that handles the plugin's settings page. The function processes POST requests to update plugin options via update_option() without any wp_nonce_field() in the form or wp_verify_nonce()/check_admin_referer() verification before processing. This makes it possible for unauthenticated attackers to modify plugin settings (toggling display options for PDF, RSS, podcast, media player links, playlist title, and playlist code) via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CWE CWE-352
Vendor edckwt
Product quran translations
Published Apr 8, 2026
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for edckwt quran translations

Be the first to know when new medium vulnerabilities affecting edckwt quran translations are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

edckwt / Quran Translations
0 โ‰ค 1.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/e30379bf-0ea1-4443-81bb-4337a0311ed3?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/quran-translations-by-edc/trunk/playlist.php#L143 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/quran-translations-by-edc/tags/1.7/playlist.php#L143 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/quran-translations-by-edc/trunk/playlist.php#L167 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/quran-translations-by-edc/tags/1.7/playlist.php#L167

Credits

Muhammad Afnaan