The Guardian News Feed plugin for WordPress suffers from a Cross-Site Request Forgery (CSRF) vulnerability in versions up to 1.2. This flaw allows attackers to change plugin settings, including the API key, by exploiting the missing nonce validation.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.