
CVE-2026-1390 The Redirect countdown plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validati… https://www.cve.org/CVERecord?id=CVE-2026-1390
Post summary
The Redirect countdown WordPress plugin is vulnerable to CSRF due to missing nonce validation in versions up to and including 1.0, as disclosed in the CVE record.
