CVE-2026-4070 | pftool Alfie Plugin up to 1.2.1 on WordPress GET Parameter alfie_manage delete cross-site request forgery

SecurityVulns

A vulnerability marked as problematic has been reported in pftool Alfie Plugin up to 1.2.1 on WordPress. This vulnerability affects the function alfie_manage of the component GET Parameter Handler. The manipulation of the argument delete leads to cross-site request forgery.

This vulnerability is traded as CVE-2026-4070. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More