CVE-2026-6451Disclosure

LOWCVSS 4.3 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.0.0. This is due to missing nonce validation on all eight AJAX deletion handlers: vehicles_cfmw_d_vehicle, contacts_cfmw_d_contact, suppliers_cfmw_d_supplier, receipts_cfmw_d_receipt, positions_cfmw_d_position, catalogs_cfmw_d_article, stock_cfmw_d_item, and settings_cfmw_d_catalog. None of these handlers call check_ajax_referer() or wp_verify_nonce(), nor do they perform any capability checks via current_user_can(). This makes it possible for unauthenticated attackers to delete arbitrary vehicles, contacts, suppliers, receipts, positions, catalog articles, stock items, or entire supplier catalogs via a forged request, provided they can trick a logged-in user into performing an action such as clicking a link to a malicious page.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-17: 2PoC Mentioned / Linked · 2026-04-17: 1Technical Details · 2026-04-17: 104-17
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6451-cms-fuer-motorrad-werkstaetten-version-1-0-0-medium-vulnerability-proof-of-concept CVE-2026-6451 #WordPress plugin #vulnerability cms-fuer-motorrad-werkstaetten #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecur…

    Post summary

    The post links to a proof‑of‑concept for CVE‑2026‑6451, a medium‑severity vulnerability in a WordPress plugin for Motorrad Werkstätten, but it does not provide exploit code, evidence of active exploitation, or patch information.

    0000041
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6451 The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.0.0. This is due to missing nonce … https://www.cve.org/CVERecord?id=CVE-2026-6451

    Post summary

    The post announces that the cms-fuer-motorrad-werkstaetten WordPress plugin is vulnerable to CSRF due to a missing nonce, without indicating active exploitation, PoC, or patch availability.

    0000055
    57.2K followersView on X

Explore more