CVE-2026-45161: Wger-Project Wger
Medium severity, CVSS 5.4. EPSS: 0.1% chance of exploitation in the next 30 days.
wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `<img>` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. Version 2.6 fixes the issue.
Affected products
- Wger-Project Wger: before 2.6 (fixed in 2.6)
Published 2026-10-07. Last modified 2026-10-07.