plugin

Textp2P Texting Widget Vulnerabilities

1 known security issue reported for the Textp2P Texting Widget WordPress plugin. Most recent disclosed Apr 21, 2026.

1 medium

Running Textp2P Texting Widget on your site? Check whether your installed version is affected.

Scan your site free

TextP2P Texting Widget <= 1.8 - Cross-Site Request Forgery to Settings Update

medium

The TextP2P Texting Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.8. This is due to missing nonce validation in the imTextP2POptionPage() function which processes settings updates. The form at line 314 does not include a wp_nonce_field(), and the POST hand...

CVSS:
4.3
Affected:
up to 1.8
Fixed in:
1.9
Disclosed:
Apr 21, 2026

CVE-2026-4133 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database