Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4133

17
FAUCET Score

BRIEFING NOTE - CVE-2026-4133 The TextP2P Texting Widget plugin for WordPress versions up to 1.7 contains a Cross-Site Request Forgery vulnerability affecting plugin settings management. The vulnerability exists because the imTextP2POptionPage() function lacks proper nonce validation mechanisms, failing to implement either wp_nonce_field() in the form or check_admin_referer() in the POST handler. An unauthenticated attacker could exploit this by tricking a site administrator into clicking a malicious link, allowing unauthorized modification of critical plugin settings including API credentials, chat configuration, and reCAPTCHA parameters. The vulnerability carries a CVSS 3.1 score of 4.3 (Medium severity) with a network-based attack vector and low complexity. Exploitation requires user interaction but poses an integrity risk to plugin configuration and potentially sensitive API credentials. The EPSS score of 0.00005 indicates minimal probability of active exploitation, and the vulnerability is not yet listed on the Known Exploited Vulnerabilities catalog nor featured on active threat lists. Currently, there is no evidence of active exploitation in the wild. No public exploit code is available, and community attention remains low as reflected in the inactive hot list status and low FAUCET risk score of 29.0. Site administrators should implement plugin updates when available and consider restricting administrative access as a compensating control.

Impacted Technologies

VendorProductVersion(s)CPE
Textp2pTextP2P Texting Widget
>= 0, <= 1.7CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 4th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / browser/textp2p-texting-widget/tags/1.7/inc/admin/im-textp2p-options.php
plugins.trac.wordpress.org / browser/textp2p-texting-widget/tags/1.7/inc/admin/im-textp2p-options.php
plugins.trac.wordpress.org / browser/textp2p-texting-widget/trunk/inc/admin/im-textp2p-options.php
plugins.trac.wordpress.org / browser/textp2p-texting-widget/trunk/inc/admin/im-textp2p-options.php
wordfence.com / threat-intel/vulnerabilities/id/2d36fa25-108b-462b-b84e-2e77943b1871