CVE-2026-6294Disclosure

LOWCVSS 4.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4. This is due to missing nonce validation in the gpdisplay_option() function, which handles the plugin settings page. The settings form does not include a wp_nonce_field(), and the form handler does not call check_admin_referer() or wp_verify_nonce() before processing the POST request. This makes it possible for unauthenticated attackers to trick a logged-in administrator into submitting a crafted request that changes the plugin's settings (stored via update_option()), such as the display style used to render the PageRank badge.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-22); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-22: 3Mentions · 2026-04-25: 1PoC Mentioned / Linked · 2026-04-25: 1Technical Details · 2026-04-22: 304-2204-25
Signal classification3 categories
Disclosure
250.0%
General
125.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-223
Disclosure2General1
2026-04-251
PoC1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-6294 The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4. This is due to missing nonce validatio… https://www.cve.org/CVERecord?id=CVE-2026-6294

    Post summary

    The text announces a new CSRF vulnerability in the Google PageRank Display WordPress plugin, affecting versions up to 1.4 due to missing nonce validation, but provides no PoC, exploit code, or mitigation details.

    00010378
    57.2K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6294-google-pagerank-display-version-1-4-medium-vulnerability-proof-of-concept CVE-2026-6294 #WordPress plugin #vulnerability google-pagerank-display #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post shares a link to a proof‑of‑concept for CVE‑2026‑6294, highlighting a medium‑severity vulnerability in the Google Pagerank Display plugin, but provides no signs of active exploitation, patches, or detailed technical specifics.

    0000042
    6 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6294 The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4. This is due to missing nonce validatio… https://www.cve.org/CVERecord?id=CVE-2026-6294 ----- Traducción: CVE-2026-6294. El… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-6294, a CSRF flaw in the Google PageRank Display WordPress plugin (v1.4 and earlier), providing only basic technical details and no PoC, exploit, patch, or evidence of active exploitation.

    0000043
    72 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6294 Cross-Site Request Forgery in Google PageRank Display Plugin for WordPress 1.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6294

    Post summary

    The post provides a brief notification of a CVE detailing a CSRF vulnerability in a WordPress plugin, but lacks any PoC, exploit, patch, or active exploitation information.

    0000052
    4.0K followersView on X

Explore more