Cross Site Request Forgery in Popup for CF7 by WordPress
CVE-2026-65540

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-65540?

This vulnerability allows an unauthenticated user to send unauthorized requests on behalf of a legitimate user. Specifically, it affects users of the Popup for CF7 with Sweet Alert plugin in versions 1.6.5 and earlier, potentially enabling attackers to exploit user sessions without consent.

Affected Version(s)

Popup for CF7 with Sweet Alert <= 1.6.5

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

testoun | Patchstack Bug Bounty Program
.