PT-2026-7496 · WordPress · Mma Call Tracking

·

CVE-2026-1215

·

Publicado

2026-02-11

·

Atualizado

2026-02-11

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress plugin MMA Call Tracking versions prior to 2.3.16
Description The MMA Call Tracking plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF). This is because of a lack of nonce validation when saving plugin configuration on the mma call tracking menu admin page. An attacker could potentially modify call tracking configuration settings by tricking a site administrator into performing an action, such as clicking a malicious link. The vulnerable setting is modified via a forged request.
Recommendations Update the MMA Call Tracking plugin to version 2.3.16 or later.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1215

Produtos afetados

Mma Call Tracking