Cross-Site Request Forgery Vulnerability in Call To Action Plugin by WordPress
CVE-2026-4118
4.3MEDIUM
What is CVE-2026-4118?
The Call To Action Plugin for WordPress is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in its settings management functions. The missing nonce check allows unauthenticated attackers to manipulate critical plugin settings, including the call-to-action box configuration. By exploiting this vulnerability, attackers can alter title, content, link URLs, image URLs, colors, and other settings by tricking an administrator into submitting a malicious request.
Affected Version(s)
Call To Action Plugin 0 <= 3.1.3