The Inquiry Cart and mCatFilter WordPress plugins are vulnerable to Cross-Site Request Forgery due to missing nonce verification in their respective functions.
Claims
The Inquiry Cart and mCatFilter WordPress plugins are vulnerable to Cross-Site Request Forgery due to missing nonce verification in their respective functions.
Parent: CybersecurityEntity: WordPress pluginsSub-entity: Inquiry Cart and mCatFilterImpact: negativeDate: Apr 22, 2026Target: The security of WordPress plugins
Source posts
๐จ EUVD-2026-24680
๐ Score: 4.3/10 (CVSS v3.1)
๐ฆ Product: mCatFilter
๐ข Vendor: chsxf
๐
Updated: 2026-04-22
๐ The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verification and capability checks in the compute_post() function, which processes settin...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24680
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24656
๐ Score: 6.1/10 (CVSS v3.1)
๐ฆ Product: Inquiry cart
๐ข Vendor: ravster
๐
Updated: 2026-04-22
๐ The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing nonce verification in the rd_ic_settings_page function when processing settings form submissions. This ...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24656
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability