
CVE-2026-7615 The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.3. This is due to missing or incorrect non… https://www.cve.org/CVERecord?id=CVE-2026-7615
Post summary
The text announces that the Widget Context WordPress plugin, versions up to 1.3.3, is vulnerable to CSRF due to missing or incorrect nonces, as documented in CVE‑2026‑7615.
