PT-2026-63951 · Metin Saraç+1 · Popup For Cf7 With Sweet Alert+1
CVE-2026-65540
·
Published
2026-07-23
·
Updated
2026-07-23
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Popup for CF7 with Sweet Alert versions prior to 1.6.6
Description
An unauthenticated Cross-Site Request Forgery (CSRF) issue exists in the Popup for CF7 with Sweet Alert plugin for WordPress. This occurs due to missing or incorrect nonce validation—a security mechanism used to ensure that a request was intentionally sent by the user—on a function. This allows an attacker to perform unauthorized actions by tricking a site administrator into clicking a malicious link.
Recommendations
Update to a version newer than 1.6.5.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Popup For Cf7 With Sweet Alert
Cf7-Sweet-Alert-Popup