PT-2026-63951 · Metin Saraç+1 · Popup For Cf7 With Sweet Alert+1

CVE-2026-65540

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Popup for CF7 with Sweet Alert versions prior to 1.6.6
Description An unauthenticated Cross-Site Request Forgery (CSRF) issue exists in the Popup for CF7 with Sweet Alert plugin for WordPress. This occurs due to missing or incorrect nonce validation—a security mechanism used to ensure that a request was intentionally sent by the user—on a function. This allows an attacker to perform unauthorized actions by tricking a site administrator into clicking a malicious link.
Recommendations Update to a version newer than 1.6.5.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65540

Affected Products

Popup For Cf7 With Sweet Alert
Cf7-Sweet-Alert-Popup