CVE-2026-81432
Received Received - Intake

JetStyleManager for Gutenberg Plugin CSRF Vulnerability

Vulnerability report for CVE-2026-81432, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX actions, allowing attackers to make a logged-in user with the edit_posts capability (Contributor and above) delete or modify custom widget skins via a crafted request, provided they can trick the user into performing an action such as clicking a link.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
jetstylemanager jetstylemanager to 1.3.9 (exc)
jetstylemanager gutenberg_wordpress_plugin to 1.3.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in the JetStyleManager plugin for WordPress versions before 1.3.9. It allows attackers to trick logged-in users with the edit_posts capability into deleting or modifying custom widget skins via malicious requests.

Detection Guidance

To detect this vulnerability, check the installed version of the JetStyleManager plugin in your WordPress admin panel. If the version is below 1.3.9, the system is vulnerable. You can also inspect network traffic for suspicious AJAX requests to widget skin modification endpoints.

Impact Analysis

If exploited, this vulnerability could allow attackers to modify or delete custom widget skins on your WordPress site without your direct consent. This requires tricking a logged-in user with sufficient permissions into performing an action like clicking a link.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized modifications or deletions of custom widget skins. If exploited, it may lead to unauthorized changes in WordPress sites, potentially affecting data integrity or user access controls. However, the specific impact depends on how the plugin is used in a given environment.

Mitigation Strategies

Immediately update the JetStyleManager plugin to version 1.3.9 or later through the WordPress admin panel. If updating is not possible, consider disabling the plugin until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81432. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart