PatchSiren cyber security CVE debrief
CVE-2026-8418 askywhale CVE debrief
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Games Catalog WordPress plugin (versions ≤1.2.0). The gc_crud() function fails to validate nonces when processing delete actions via GET requests, allowing unauthenticated attackers to forge requests that delete arbitrary game catalog entries and their associated WordPress posts if an administrator clicks a malicious link. The vulnerability was disclosed on 2026-05-20 with a CVSS 3.1 score of 4.3 (Medium). No known exploitation in the wild has been reported.
- Vendor
- askywhale
- Product
- Games Catalog
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-07-23
Who should care
WordPress site administrators using the Games Catalog plugin, security teams monitoring WordPress plugin vulnerabilities, and developers maintaining WordPress plugins with administrative CRUD functionality
Technical summary
The Games Catalog plugin registers the gc_crud() function to handle administrative CRUD operations. When processing action=delete via GET request, the function lacks wp_verify_nonce() or check_admin_referer() validation. This missing protection allows attackers to construct URLs that, when visited by an authenticated administrator, execute deletion of arbitrary game catalog entries and their associated WordPress posts without the administrator's intentional consent. The vulnerability is present in both the 1.2.0 tagged release and current trunk code as of disclosure.
Defensive priority
medium
Recommended defensive actions
- Update the Games Catalog WordPress plugin to a version newer than 1.2.0 when available
- Implement additional CSRF protections for administrative actions if running affected versions
- Review administrator activity logs for unexpected game catalog deletions around 2026-05-20 and later
- Consider implementing Content Security Policy (CSP) and SameSite cookie attributes to mitigate CSRF risks
- Monitor WordPress plugin repository for security patches to the game-catalog plugin
Evidence notes
The vulnerability is documented in WordPress plugin repository source code references showing the gc_crud() function at admin-crud.php line 31 and line 94, with the function hook registration at games-catalog.php line 96. The issue affects both the tagged 1.2.0 release and trunk versions. Wordfence assigned CWE-352 (Cross-Site Request Forgery).
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8418 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8418
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8418 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8418
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/game-catalog/tags/1.2.0/admin-crud.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/game-catalog/tags/1.2.0/admin-crud.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/game-catalog/tags/1.2.0/games-catalog.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/game-catalog/trunk/admin-crud.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/game-catalog/trunk/admin-crud.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/game-catalog/trunk/games-catalog.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.