
CVE-2026-4118 The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.3. This is due to missing nonce val… https://www.cve.org/CVERecord?id=CVE-2026-4118
Post summary
The CVE reveals a CSRF flaw in the Call To Action WordPress plugin (v≤3.1.3) caused by missing nonce validation; no PoC, exploit, or patch details are provided.

