# CVE-2026-4139

> Vulnerability · severity: **MEDIUM** (CVSS 4.3).

## Description

The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verification and capability checks in the compute_post() function, which processes settings updates. The compute_post() function is called in the plugin constructor on every page load via the plugins_loaded hook, and it directly processes $_POST data to modify plugin settings via update_option() without any CSRF token validation. This makes it possible for unauthenticated attackers to modify all plugin settings, including category exclusion rules, feed exclusion flags, and tag page exclusion flags, via a forged POST request, granted they can trick a site administrator into performing an action such as clicking a link.

## Key facts

- **CVE ID:** CVE-2026-4139
- **Published:** 2026-04-22
- **CVSS severity:** MEDIUM
- **CVSS base score:** 4.3
- **CWE codes:** CWE-352

## Primary sources

- NIST NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-4139

## Citation

> AI Analytics. CVE-2026-4139. Retrieved 2026-07-21 from https://api.ai-analytics.org/cve/CVE-2026-4139. Derived from NIST NVD. Licensed CC0.

---

*[Dataset catalog](https://api.ai-analytics.org/datasets/) · [AI Analytics](https://api.ai-analytics.org/) · CC0 1.0*