PT-2026-7496 · WordPress · Mma Call Tracking

Muhammad Afnaan

·

Published

2026-02-11

·

Updated

2026-02-11

·

CVE-2026-1215

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress plugin MMA Call Tracking versions prior to 2.3.16
Description The MMA Call Tracking plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF). This is because of a lack of nonce validation when saving plugin configuration on the mma call tracking menu admin page. An attacker could potentially modify call tracking configuration settings by tricking a site administrator into performing an action, such as clicking a malicious link. The vulnerable setting is modified via a forged request.
Recommendations Update the MMA Call Tracking plugin to version 2.3.16 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-1215

Affected Products

Mma Call Tracking