โ† All reports

The Inquiry Cart and mCatFilter WordPress plugins are vulnerable to Cross-Site Request Forgery due to missing nonce verification in their respective functions.

CybersecurityWordpressApr 22, 2026score 0.172 posts ยท 0 replies across 1 instances
The thread reports two separate vulnerabilities in WordPress plugins, both related to Cross-Site Request Forgery (CSRF) issues. These vulnerabilities affect specific versions of the Inquiry Cart and mCatFilter plugins, highlighting security risks in WordPress plugin development.

Claims

The Inquiry Cart and mCatFilter WordPress plugins are vulnerable to Cross-Site Request Forgery due to missing nonce verification in their respective functions.
Parent: CybersecurityEntity: WordPress pluginsSub-entity: Inquiry Cart and mCatFilterImpact: negativeDate: Apr 22, 2026Target: The security of WordPress plugins

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24680 ๐Ÿ“Š Score: 4.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: mCatFilter ๐Ÿข Vendor: chsxf ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verification and capability checks in the compute_post() function, which processes settin... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24680 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24656 ๐Ÿ“Š Score: 6.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Inquiry cart ๐Ÿข Vendor: ravster ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing nonce verification in the rd_ic_settings_page function when processing settings form submissions. This ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24656 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability