Cross-Site Request Forgery Vulnerability in Tm – WordPress Redirection Plugin
CVE-2026-7561
6.1MEDIUM
What is CVE-2026-7561?
The Tm – WordPress Redirection plugin is susceptible to Cross-Site Request Forgery (CSRF) due to inadequate nonce validation. This vulnerability allows unauthenticated attackers to alter settings and inject malicious scripts by tricking a site administrator into clicking a malicious link. Ensuring proper validation and authentication measures is crucial for safeguarding against such exploits.
Affected Version(s)
Tm – WordPress Redirection 0 <= 1.2