What is CVE-2026-28172?
This vulnerability allows unauthenticated Cross-Site Request Forgery (CSRF) attacks in Tracking Code Manager plugin versions 2.6.0 and below. Affected systems could be tricked into performing unintended actions on behalf of authenticated users. Immediate update to the latest version is recommended.
Azərbaycanca: Bu boşluq Tracking Code Manager plaginin 2.6.0 və aşağı versiyalarında autentifikasiya olmadan CSRF hücumuna imkan verir. Təsirlənmiş sistemlərdə istifadəçilər aldadılaraq arzuolunmaz əməliyyatlar icra edilə bilər. Dərhal plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which versions of the Tracking Code Manager plugin are affected by CVE-2026-28172?
CVE-2026-28172 affects Tracking Code Manager plugin versions 2.6.0 and below.
What action is recommended to mitigate CVE-2026-28172?
To mitigate CVE-2026-28172, it is recommended to immediately update the Tracking Code Manager plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.