CVE-2026-3332 | xhanch_studio Xhanch Plugin up to 1.1.2 on WordPress Setting xms_setting favicon_url/ga_acc_id cross-site request forgery
A vulnerability marked as problematic has been reported in xhanch_studio Xhanch Plugin up to 1.1.2 on WordPress. Affected is the function xms_setting of the component Setting Handler. The manipulation of the argument favicon_url/ga_acc_id leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2026-3332. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.