
CVE-2026-1082 The TITLE ANIMATOR plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation o… https://www.cve.org/CVERecord?id=CVE-2026-1082
Post summary
The CVE-2026-1082 entry announces a CSRF flaw in the WordPress TITLE ANIMATOR plugin (v1.0 and earlier) due to missing nonce validation, with no PoC, exploit, or patch details provided.
