PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8418 askywhale CVE debrief

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Games Catalog WordPress plugin (versions ≤1.2.0). The gc_crud() function fails to validate nonces when processing delete actions via GET requests, allowing unauthenticated attackers to forge requests that delete arbitrary game catalog entries and their associated WordPress posts if an administrator clicks a malicious link. The vulnerability was disclosed on 2026-05-20 with a CVSS 3.1 score of 4.3 (Medium). No known exploitation in the wild has been reported.

Vendor
askywhale
Product
Games Catalog
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-20
Original CVE updated
2026-07-23
Advisory published
2026-05-20
Advisory updated
2026-07-23

Who should care

WordPress site administrators using the Games Catalog plugin, security teams monitoring WordPress plugin vulnerabilities, and developers maintaining WordPress plugins with administrative CRUD functionality

Technical summary

The Games Catalog plugin registers the gc_crud() function to handle administrative CRUD operations. When processing action=delete via GET request, the function lacks wp_verify_nonce() or check_admin_referer() validation. This missing protection allows attackers to construct URLs that, when visited by an authenticated administrator, execute deletion of arbitrary game catalog entries and their associated WordPress posts without the administrator's intentional consent. The vulnerability is present in both the 1.2.0 tagged release and current trunk code as of disclosure.

Defensive priority

medium

Recommended defensive actions

  • Update the Games Catalog WordPress plugin to a version newer than 1.2.0 when available
  • Implement additional CSRF protections for administrative actions if running affected versions
  • Review administrator activity logs for unexpected game catalog deletions around 2026-05-20 and later
  • Consider implementing Content Security Policy (CSP) and SameSite cookie attributes to mitigate CSRF risks
  • Monitor WordPress plugin repository for security patches to the game-catalog plugin

Evidence notes

The vulnerability is documented in WordPress plugin repository source code references showing the gc_crud() function at admin-crud.php line 31 and line 94, with the function hook registration at games-catalog.php line 96. The issue affects both the tagged 1.2.0 release and trunk versions. Wordfence assigned CWE-352 (Cross-Site Request Forgery).

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8418 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8418

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8418 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8418

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.