
CVE-2026-4121 The Kcaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.1. This is due to missing nonce validation in the … https://www.cve.org/CVERecord?id=CVE-2026-4121
Post summary
The post announces a CSRF vulnerability (CVE-2026-4121) in the Kcaptcha WordPress plugin caused by missing nonce validation in versions up to 1.0.1, with no evidence of PoC, exploits, or patches.

