
CVE-2026-1087 The Guardian News Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing nonce validati… https://www.cve.org/CVERecord?id=CVE-2026-1087
Post summary
CVE-2026-1087 identifies a CSRF vulnerability in the Guardian News Feed WordPress plugin up to version 1.2 caused by missing nonce validation; no PoC, exploit, patch, or active exploitation is reported.

