CVE-2026-8940 | jasonpitts WP Meta Sort Posts Plugin up to 0.9 on WordPress Setting msp-options.php msp_nav_location cross-site request forgery
A vulnerability classified as problematic has been found in jasonpitts WP Meta Sort Posts Plugin up to 0.9 on WordPress. This issue affects some unknown processing of the file msp-options.php of the component Setting Handler. Performing a manipulation of the argument msp_nav_location results in cross-site request forgery.
This vulnerability is reported as CVE-2026-8940. The attack is possible to be carried out remotely. No exploit exists.