Vulnerability Description
The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to both wp_ajax_* and wp_ajax_nopriv_* hooks and unconditionally calls delete_option() on four plugin options and delete_transient() on three transients tied to the plugin's API key cache and settings. This makes it possible for unauthenticated attackers to delete plugin options and transients, effectively resetting the plugin's API key/data cache and forcing the plugin to refetch state.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/fense-block-vpn-proxy/tags/2.9.0/incl
- https://plugins.trac.wordpress.org/browser/fense-block-vpn-proxy/tags/2.9.0/incl
- https://plugins.trac.wordpress.org/browser/fense-block-vpn-proxy/tags/3.0.2/incl
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1208ac78-4a56-4daa-b93
FAQ
What is CVE-2026-8616?
CVE-2026-8616 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() f...
How severe is CVE-2026-8616?
CVE-2026-8616 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-8616?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.