plugin

Feedzy Rss Feeds Vulnerabilities

31 known security issues reported for the Feedzy Rss Feeds WordPress plugin. Most recent disclosed Aug 6, 2026.

1 high 15 medium

Running Feedzy Rss Feeds on your site? Check whether your installed version is affected.

Scan your site free

RSS Aggregator by Feedzy <= 5.2.5 - Missing Authorization to Authenticated (Author+) Cross-User Import Job Manipulation and Post Deletion

medium

The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 5.2.5. This is due to missing authorization checks on AJAX handlers for import job actions, allowing any authenticated user to act on posts they do not own. This makes it possible for authenticated a...

CVSS:
4.3
Affected:
up to 5.2.5
Fixed in:
5.2.6
Disclosed:
Aug 6, 2026

CVE-2026-18934 on NVD →

Feedzy <= 5.2.4 - Authenticated (Contributor+) Server-Side Request Forgery

medium

The Feedzy plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5.2.4. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query a...

CVSS:
6.4
Affected:
up to 5.2.4
Fixed in:
5.2.5
Disclosed:
Jul 27, 2026

CVE-2026-66437 on NVD →

RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute

medium

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'aspectRatio' Attribute in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible fo...

CVSS:
6.4
Affected:
up to 5.2.1
Fixed in:
5.2.2
Disclosed:
Jul 1, 2026

CVE-2026-13252 on NVD →

RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-Actions

medium

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible...

CVSS:
4.3
Affected:
up to 5.1.7
Fixed in:
5.1.8
Disclosed:
Jun 5, 2026

CVE-2026-8976 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.1.2

unknown

[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 5.1.1 via the feedzy_lazy_load function. This makes it possible for unauthenticated attackers to make web re...

Affected:
up to 5.1.2
Fixed in:
5.1.2
Disclosed:
Dec 11, 2025

CVE-2025-11467 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated Blind Server-Side Request Forgery

medium

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 5.1.1 via the feedzy_lazy_load function. This makes it possible for unauthenticated attackers to make web request...

CVSS:
5.8
Affected:
up to 5.1.1
Fixed in:
5.1.2
Disclosed:
Dec 10, 2025

CVE-2025-11467 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.1.1 (closed)

unknown

[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds' function. This makes it possible for authenticated attackers, with Subscribe...

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Oct 23, 2025

CVE-2025-11128 on NVD →

Feedzy RSS Feeds Lite <= 5.1.0 - Authenticated (Subscriber+) Server-Side Request Forgery

medium

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds' function. This makes it possible for authenticated attackers, with Subscriber-lev...

CVSS:
5
Affected:
up to 5.1.0
Fixed in:
5.1.1
Disclosed:
Oct 22, 2025

CVE-2025-11128 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.8 (closed)

unknown

[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 4.4.7 via the fetch_feed functionality. This makes it possible for authenticated attackers, with contributor...

Affected:
up to 4.4.8
Fixed in:
4.4.8
Disclosed:
Apr 17, 2024

CVE-2023-6805 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF)

medium

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 4.4.7 via the fetch_feed functionality. This makes it possible for authenticated attackers, with contributor acce...

CVSS:
6.4
Affected:
up to 4.4.7
Fixed in:
4.4.8
Disclosed:
Apr 16, 2024

CVE-2023-6805 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.3.4 (closed)

unknown

[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping on the Content-Type...

Affected:
up to 4.3.4
Fixed in:
4.3.4
Disclosed:
Apr 7, 2024

CVE-2023-6877 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error Message

medium

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping on the Content-Type fiel...

CVSS:
6.4
Affected:
up to 4.3.3
Fixed in:
4.3.4
Disclosed:
Apr 6, 2024

CVE-2023-6877 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.3 (closed)

unknown

[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'feedzy_wizard_step_process' and 'import_status' functions in all versions up to, and including, 4.4.2. T...

Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
Feb 20, 2024

CVE-2024-1318 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.3 (closed)

unknown

[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection via the ‘search_key’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparat...

Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
Feb 20, 2024

CVE-2024-1317 on NVD →

RSS Aggregator by Feedzy <= 4.4.2 - Authenticated(Contributor+) SQL Injection

high

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection via the ‘search_key’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o...

CVSS:
8.8
Affected:
up to 4.4.2
Fixed in:
4.4.3
Disclosed:
Feb 9, 2024

CVE-2024-1317 on NVD →

RSS Aggregator by Feedzy <= 4.4.2 - Missing Authorization to Arbitrary Page Creation and Publication

medium

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'feedzy_wizard_step_process' and 'import_status' functions in all versions up to, and including, 4.4.2. This m...

CVSS:
6.5
Affected:
up to 4.4.2
Fixed in:
4.4.3
Disclosed:
Feb 9, 2024

CVE-2024-1318 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.2 (closed)

unknown

[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and including, 4.4.1. This makes it possible for authenticated attac...

Affected:
up to 4.4.2
Fixed in:
4.4.2
Disclosed:
Feb 5, 2024

CVE-2024-1092 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing Authorization

medium

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers,...

CVSS:
4.3
Affected:
up to 4.4.1
Fixed in:
4.4.2
Disclosed:
Feb 2, 2024

CVE-2024-1092 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.2 (closed)

unknown

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers,...

Affected:
up to 4.4.2
Fixed in:
4.4.2
Disclosed:
Feb 2, 2024

ThemeIsle SDK <= Various Versions - Missing Authorization

medium

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to update options values that allow ThemeIsle to track...

CVSS:
5.3
Affected:
up to 4.4.1
Fixed in:
4.4.2
Disclosed:
Feb 1, 2024

CVE-2024-1047 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.3.3 (closed)

unknown

[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for au...

Affected:
up to 4.3.3
Fixed in:
4.3.3
Disclosed:
Jan 6, 2024

CVE-2023-6801 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.3.3 (closed)

unknown

[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check when updating settings in all versions up to, and including, 4.3.2. This makes it possible for authenticated attacker...

Affected:
up to 4.3.3
Fixed in:
4.3.3
Disclosed:
Jan 6, 2024

CVE-2023-6798 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authent...

CVSS:
6.4
Affected:
up to 4.3.2
Fixed in:
4.3.3
Disclosed:
Jan 5, 2024

CVE-2023-6801 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Missing Authorization

medium

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check when updating settings in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, wi...

CVSS:
5.4
Affected:
up to 4.3.2
Fixed in:
4.3.3
Disclosed:
Jan 5, 2024

CVE-2023-6798 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 3.4.3 (closed)

unknown

[en] The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it possible for unauthenticated attackers to update post meta via a fo...

Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Oct 20, 2023

CVE-2020-36758 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 3.4.3 (closed)

unknown
Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.1.1 (closed)

unknown

[en] The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such a...

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Jan 30, 2023

CVE-2022-4667 on NVD →

RSS Aggregator by Feedzy <= 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor l...

CVSS:
6.4
Affected:
up to 4.1.0
Fixed in:
4.1.1
Disclosed:
Jan 4, 2023

CVE-2022-4667 on NVD →

RSS Aggregator by Feedzy <= 3.4.2 - Cross-Site Request Forgery Bypass

medium

The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it possible for unauthenticated attackers to update post meta via a forged...

CVSS:
4.3
Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Sep 16, 2020

CVE-2020-36758 on NVD →

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 3.4.3 (closed)

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress RSS Aggregator by Feedzy plugin (versions <= 3.4.2).

Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Sep 16, 2020

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News &amp; YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 3.4.3 (closed)

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 3.4.3
Fixed in:
3.4.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database