CVE-2026-8904 | yuluma FastPicker Plugin up to 1.0.2 on WordPress API settingsPage cross-site request forgery
A vulnerability has been found in yuluma FastPicker Plugin up to 1.0.2 on WordPress and classified as problematic. This affects the function settingsPage of the component API. This manipulation causes cross-site request forgery.
This vulnerability is handled as CVE-2026-8904. The attack can be initiated remotely. There is not any exploit available.