A vulnerability marked as problematic has been reported in udamadu Inquiry Form to Posts or pages Plugin up to 1.0 on WordPress. This issue affects the function check_admin_referer. Performing a manipulation of the argument inq_hidden results in cross-site request forgery.

This vulnerability is cataloged as CVE-2026-6293. It is possible to initiate the attack remotely. There is no exploit available.