PT-2026-34292 · Sphex1987 · Wp Responsive Popup + Optin
Published
2026-04-22
·
Updated
2026-04-22
·
CVE-2026-4131
CVSS v3.1
6.1
Medium
| AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due to the settings form on the admin page (wpo admin page.php) lacking nonce generation (wp nonce field) and verification (wp verify nonce/check admin referer). This makes it possible for unauthenticated attackers to update all plugin settings including the 'wpo image url' parameter via a forged request, granted they can trick a site administrator into performing an action such as clicking a link.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Responsive Popup + Optin