CVE-2026-4090Disclosure

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing nonce verification in the rd_ic_settings_page function when processing settings form submissions. This makes it possible for unauthenticated attackers to update the plugin's settings, including injecting malicious scripts that will be stored and executed in the admin area, via a forged request granted they can trick an administrator into performing an action such as clicking on a link.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-23: 2PoC Mentioned / Linked · 2026-04-23: 1Exploit Tool / Code · 2026-04-23: 1Technical Details · 2026-04-23: 104-23
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4090 The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing nonce verification… https://www.cve.org/CVERecord?id=CVE-2026-4090

    Post summary

    The Inquiry Cart plugin for WordPress is vulnerable to CSRF attacks caused by missing nonce verification in all versions up to 3.4.2.

    00000116
    57.2K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4090-inquiry-cart-version-3-4-2-medium-vulnerability-proof-of-concept CVE-2026-4090 #WordPress plugin #vulnerability inquiry-cart #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post advertises a proof‑of‑concept exploit for CVE‑2026‑4090 targeting the Inquiry‑Cart WordPress plugin (v3.4.2), indicating a medium‑severity vulnerability, but offers no evidence of active exploitation or any mitigation.

    0000045
    6 followersView on X

Explore more