CVE-2026-4139 Details
Description
The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verification and capability checks in the compute_post() function, which processes settings updates. The compute_post() function is called in the plugin constructor on every page load via the plugins_loaded hook, and it directly processes $_POST data to modify plugin settings via update_option() without any CSRF token validation. This makes it possible for unauthenticated attackers to modify all plugin settings, including category exclusion rules, feed exclusion flags, and tag page exclusion flags, via a forged POST request, granted they can trick a site administrator into performing an action such as clicking a link.
A Cross-Site Request Forgery (CSRF) vulnerability exists in the mCatFilter plugin for WordPress, affecting all versions up to and including 0.5.2. The vulnerability arises from the lack of nonce verification and capability checks in the compute_post() function, which handles settings updates. This function is invoked on every page load through the plugins_loaded hook, processing $_POST data to change plugin settings via update_option() without any CSRF token validation. As a result, unauthenticated attackers can alter various plugin settings, such as category exclusion rules and feed exclusion flags, by sending a forged POST request that tricks a site administrator into clicking a link.
No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 22, 2026CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://plugins.trac.wordpress.org/browser/mcatfilter/tags/0.5.2/mcatfilter.php#L138 | [email protected] | Broken LinkSource CodeVendor |
| https://plugins.trac.wordpress.org/browser/mcatfilter/tags/0.5.2/mcatfilter.php#L320 | [email protected] | Broken LinkSource CodeVendor |
| https://plugins.trac.wordpress.org/browser/mcatfilter/tags/0.5.2/mcatfilter.php#L339 | [email protected] | Broken LinkSource CodeVendor |
| https://plugins.trac.wordpress.org/browser/mcatfilter/trunk/mcatfilter.php#L138 | [email protected] | Broken LinkSource CodeVendor |
| https://plugins.trac.wordpress.org/browser/mcatfilter/trunk/mcatfilter.php#L320 | [email protected] | Broken LinkSource CodeVendor |
| https://plugins.trac.wordpress.org/browser/mcatfilter/trunk/mcatfilter.php#L339 | [email protected] | Broken LinkSource CodeVendor |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/622ee6c8-7739-44ae-b88f-63a93c0a9b20?source=cve | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mCatFilter | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | New CVE Received | [email protected] |
Volerion