Executive brief
The Popup for CF7 with Sweet Alert plugin for WordPress is vulnerable to a security flaw that could allow an attacker to trick a site administrator into performing unintended actions. By convincing a logged-in user to click a malicious link or visit a specially crafted webpage, an attacker could potentially change plugin settings or modify site content without authorization. This could lead to unauthorized configuration changes or a loss of integrity for the affected website.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'Popup for CF7 with Sweet Alert' WordPress plugin (versions <= 1.6.5) due to missing or incorrect nonce validation on sensitive administrative functions. An unauthenticated remote attacker can exploit this by inducing a privileged user (such as an administrator) to interact with a malicious link or form. Successful exploitation allows the attacker to execute unauthorized actions in the context of the victim's session, which may include modifying plugin configurations. As of the advisory date, no official patch has been released.
Affected products
- Metin Saraç Popup for CF7 with Sweet Alert <= 1.6.5
Timeline
- 2026-06-18: other: Vulnerability reported by researcher testoun
- 2026-07-23: disclosed: Vulnerability published by Patchstack and NVD