CVE-2026-61956
HIGHhamsalam sync-basalam <= 1.9.1 - Cross-Site Request Forgery
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2026-61956. PoCs published by incogbyte.
AI-analyzed exploit summary This PoC demonstrates a CSRF vulnerability in the Basalam Sync WordPress plugin (<= 1.9.1) where an attacker can forge a GET request to the `basalam-save-token` admin page to overwrite OAuth connection settings without nonce/state validation. The exploit verifies the unauthorized settings overwrite by reading back stored values via wp-cli.
Description
Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام – همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1.
Exploits (1)
This PoC demonstrates a CSRF vulnerability in the Basalam Sync WordPress plugin (<= 1.9.1) where an attacker can forge a GET request to the `basalam-save-token` admin page to overwrite OAuth connection settings without nonce/state validation. The exploit verifies the unauthorized settings overwrite by reading back stored values via wp-cli.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N