Cross-Site Request Forgery Vulnerability in OPEN-BRAIN Plugin for WordPress
CVE-2026-4091
6.1MEDIUM
What is CVE-2026-4091?
The OPEN-BRAIN plugin for WordPress is affected by a Cross-Site Request Forgery vulnerability that exists due to the absence of nonce verification in the settings form. This flaw allows unauthorized attackers to exploit it by tricking a site administrator into executing unintended actions, such as clicking on a link. As a result, attackers could potentially inject harmful scripts into the web application, posing a significant security risk to administrators and users alike.
Affected Version(s)
OPEN-BRAIN 0 <= 0.5.0