
CVE-2026-1165 The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1.1. This is due to a flawed nonce implementation… https://www.cve.org/CVERecord?id=CVE-2026-1165
Post summary
The text discloses that the Popup Box WordPress plugin suffers from a CSRF vulnerability due to a flawed nonce implementation in versions up to 6.1.1, with no PoC, exploit, or mitigation details provided.

