
CVE-2026-4133 The TextP2P Texting Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.7. This is due to missing nonce valida… https://www.cve.org/CVERecord?id=CVE-2026-4133
Post summary
CVE-2026-4133 reveals a CSRF vulnerability in the TextP2P Texting Widget WordPress plugin (v1.7 and earlier) caused by missing nonce validation, with no exploits or mitigation details provided.
