Cross-Site Request Forgery Vulnerability in BirdSeed Plugin by WordPress
CVE-2026-4071
4.3MEDIUM
What is CVE-2026-4071?
The BirdSeed plugin for WordPress presents a Cross-Site Request Forgery vulnerability across all versions up to and including 2.2.0. The vulnerability arises from insufficient nonce validation in the birdseed_plugin_settings_page() function, which processes the 'birdseed_token' GET parameter and updates it in the database without proper verification. This oversight allows unauthorized attackers to exploit the plugin by tricking an administrator into executing a malicious request, potentially altering critical plugin settings without their consent.
Affected Version(s)
BirdSeed 0 <= 2.2.0