The Guardian News Feed - Cross-Site Request Forgery to Settings Update vulnerability
mediumCross-Site Request Forgery to Settings Update vulnerability
- CVSS:
- 4.3
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Mar 7, 2026
plugin
2 known security issues reported for the The Guardian News Feed WordPress plugin. Most recent disclosed Mar 7, 2026.
Running The Guardian News Feed on your site? Check whether your installed version is affected.
Scan your site freeCross-Site Request Forgery to Settings Update vulnerability
The Guardian News Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the Guardian AP...
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free