CVE-2026-1215 - MMA Call Tracking <= 2.3.15 - cross-site request forgery to plugin settings update

CVE-2026-1215 - MMA Call Tracking <= 2.3.15 - cross-site request forgery to plugin settings update

CVE ID : CVE-2026-1215 Published : Feb. 11, 2026, 8:26 a.m. | 49 minutes ago Description : The MMA Call Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.15. This is due to missing nonce validation when saving plugin configuration on the `mma_call_tracking_menu` admin page. This makes it possible for unauthenticated attackers to modify call tracking configuration settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
Feb. 11, 2026
Affected Product: WordPress