BRIEFING NOTE - CVE-2026-4133 The TextP2P Texting Widget plugin for WordPress versions up to 1.7 contains a Cross-Site Request Forgery vulnerability affecting plugin settings management. The vulnerability exists because the imTextP2POptionPage() function lacks proper nonce validation mechanisms, failing to implement either wp_nonce_field() in the form or check_admin_referer() in the POST handler. An unauthenticated attacker could exploit this by tricking a site administrator into clicking a malicious link, allowing unauthorized modification of critical plugin settings including API credentials, chat configuration, and reCAPTCHA parameters. The vulnerability carries a CVSS 3.1 score of 4.3 (Medium severity) with a network-based attack vector and low complexity. Exploitation requires user interaction but poses an integrity risk to plugin configuration and potentially sensitive API credentials. The EPSS score of 0.00005 indicates minimal probability of active exploitation, and the vulnerability is not yet listed on the Known Exploited Vulnerabilities catalog nor featured on active threat lists. Currently, there is no evidence of active exploitation in the wild. No public exploit code is available, and community attention remains low as reflected in the inactive hot list status and low FAUCET risk score of 29.0. Site administrators should implement plugin updates when available and consider restricting administrative access as a compensating control.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Textp2p | TextP2P Texting Widget | >= 0, <= 1.7CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.