CVE-2026-4139Disclosure

LOWCVSS 4.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verification and capability checks in the compute_post() function, which processes settings updates. The compute_post() function is called in the plugin constructor on every page load via the plugins_loaded hook, and it directly processes $_POST data to modify plugin settings via update_option() without any CSRF token validation. This makes it possible for unauthenticated attackers to modify all plugin settings, including category exclusion rules, feed exclusion flags, and tag page exclusion flags, via a forged POST request, granted they can trick a site administrator into performing an action such as clicking a link.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-22); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Mentions · 2026-04-26: 1PoC Mentioned / Linked · 2026-04-26: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-2204-2304-26
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-221
Disclosure1
2026-04-231
Disclosure1
2026-04-261
PoC1
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4139-mcatfilter-version-0-5-2-medium-vulnerability-proof-of-concept CVE-2026-4139 #WordPress plugin #vulnerability mcatfilter #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post shares a link to a proof‑of‑concept demonstrating a medium‑severity vulnerability (CVE‑2026‑4139) in the mcatfilter WordPress plugin.

    0000054
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4139 The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce … https://www.cve.org/CVERecord?id=CVE-2026-4139

    Post summary

    The mCatFilter WordPress plugin is vulnerable to CSRF because it lacks nonce validation in all versions up to 0.5.2 (CVE‑2026‑4139). No exploit, patch, or active misuse information is provided.

    00000118
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4139 Cross-Site Request Forgery in mCatFilter Plugin for WordPress Up to 0.5.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4139 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text announces a newly disclosed CSRF vulnerability affecting the mCatFilter WordPress plugin, providing basic technical details but no evidence of exploitation or mitigation.

    0000052
    4.0K followersView on X

Explore more