
CVE-2026-4070 The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce valid… https://www.cve.org/CVERecord?id=CVE-2026-4070
Post summary
CVE-2026-4070 reveals a CSRF vulnerability in Alfie – Feed Plugin up to version 1.2.1; no PoC, exploit, or patch information is provided.
