What is CVE-2026-14234?
This vulnerability exists in the WOLF WordPress plugin before version 1.1.0, where an AJAX action lacks a nonce or capability check. It allows an unauthenticated attacker to trick a logged-in administrator into injecting arbitrary content, including malicious scripts, into a post via a cross-site request. Updating the plugin to the latest version is recommended.
Azərbaycanca: Bu zəiflik WOLF WordPress plaginində 1.1.0 versiyasından əvvəl aşkarlanıb. AJAX əməliyyatlarında nonce və ya icazə yoxlanışı aparılmadığı üçün autentifikasiya olunmamış hücumçu, giriş etmiş administratoru aldadaraq posta zərərli skriptlər yerləşdirə bilər. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
In which plugin was CVE-2026-14234 discovered and what causes it?
This vulnerability exists in the WOLF WordPress plugin before version 1.1.0. It is caused by an AJAX action lacking a nonce or capability check.
What can an unauthenticated attacker do by exploiting CVE-2026-14234?
An unauthenticated attacker can trick a logged-in administrator into injecting arbitrary content, including malicious scripts, into a post.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.