CVE-2026-4131Disclosure

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due to the settings form on the admin page (wpo_admin_page.php) lacking nonce generation (wp_nonce_field) and verification (wp_verify_nonce/check_admin_referer). This makes it possible for unauthenticated attackers to update all plugin settings including the 'wpo_image_url' parameter via a forged request, granted they can trick a site administrator into performing an action such as clicking a link.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-23)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-22: 1Mentions · 2026-04-23: 2PoC Mentioned / Linked · 2026-04-23: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-2204-23
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-221
Disclosure1
2026-04-232
Disclosure1PoC1
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4131-wp-popup-optin-version-1-4-medium-vulnerability-proof-of-concept CVE-2026-4131 #WordPress plugin #vulnerability wp-popup-optin #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    A proof of concept for CVE‑2026‑4131 affecting the wp-popup-optin plugin has been made publicly available.

    0000050
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4131 The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due to the settings fo… https://www.cve.org/CVERecord?id=CVE-2026-4131

    Post summary

    CVE-2026-4131 reveals a CSRF flaw in WP Responsive Popup + Optin plugin versions up to 1.4, with no PoC, exploit, patch or active exploitation details provided.

    00000125
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4131 Cross-Site Request Forgery in WP Responsive Popup + Optin Plugin Versions Up to 1.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4131

    Post summary

    CVE-2026-4131 exposes a cross‑site request forgery flaw in WP Responsive Popup + Optin Plugin versions up to 1.4, with no mention of active exploitation, patch, or PoC.

    0000041
    4.0K followersView on X

Explore more