EXECUTIVE BRIEFING NOTE - CVE-2026-4138 OVERVIEW The DX Unanswered Comments plugin for WordPress versions up to 1.7 contains a Cross-Site Request Forgery (CSRF) vulnerability in its settings form. The vulnerability stems from missing nonce validation in the dxuc-unanswered-comments-admin-page.php file, allowing attackers to modify critical plugin settings including author lists and comment counts without proper authentication safeguards. SEVERITY This vulnerability carries a CVSS 3.1 score of 4.3 (MEDIUM) with a network-based attack vector requiring minimal complexity and user interaction. An unauthenticated attacker would need to trick a site administrator into clicking a malicious link to execute the attack. The impact is limited to integrity violations, as attackers can only modify plugin configuration settings without gaining access to sensitive data or causing service disruption. The FAUCET Risk Score of 29.0/100 indicates moderate organizational risk. EXPLOITATION STATUS There is no indication of active exploitation in the wild. The vulnerability is not included on CISA's Known Exploited Vulnerabilities (KEV) catalog and shows no presence on threat tracking hot lists. The EPSS score of 0.0001 reflects minimal real-world exploitation probability. While the vulnerability is straightforward and theoretically exploitable, community attention and exploit code availability appear limited at this time. RECOMMENDATION Organizations running affected versions should update the DX Unanswered Comments plugin to version 1.8 or later to apply nonce validation controls.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Nofearinc | DX Unanswered Comments | >= 0, <= 1.7CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.