RSS Aggregator by Feedzy <= 5.2.5 - Missing Authorization to Authenticated (Author+) Cross-User Import Job Manipulation and Post Deletion
medium
The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 5.2.5. This is due to missing authorization checks on AJAX handlers for import job actions, allowing any authenticated user to act on posts they do not own. This makes it possible for authenticated a...
- CVSS:
- 4.3
- Affected:
- up to 5.2.5
- Fixed in:
- 5.2.6
- Disclosed:
- Aug 6, 2026
CVE-2026-18934 on NVD →
Feedzy <= 5.2.4 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The Feedzy plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5.2.4. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query a...
- CVSS:
- 6.4
- Affected:
- up to 5.2.4
- Fixed in:
- 5.2.5
- Disclosed:
- Jul 27, 2026
CVE-2026-66437 on NVD →
RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute
medium
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'aspectRatio' Attribute in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible fo...
- CVSS:
- 6.4
- Affected:
- up to 5.2.1
- Fixed in:
- 5.2.2
- Disclosed:
- Jul 1, 2026
CVE-2026-13252 on NVD →
RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-Actions
medium
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible...
- CVSS:
- 4.3
- Affected:
- up to 5.1.7
- Fixed in:
- 5.1.8
- Disclosed:
- Jun 5, 2026
CVE-2026-8976 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.1.2
unknown
[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 5.1.1 via the feedzy_lazy_load function. This makes it possible for unauthenticated attackers to make web re...
- Affected:
- up to 5.1.2
- Fixed in:
- 5.1.2
- Disclosed:
- Dec 11, 2025
CVE-2025-11467 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated Blind Server-Side Request Forgery
medium
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 5.1.1 via the feedzy_lazy_load function. This makes it possible for unauthenticated attackers to make web request...
- CVSS:
- 5.8
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.2
- Disclosed:
- Dec 10, 2025
CVE-2025-11467 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.1.1 (closed)
unknown
[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds' function. This makes it possible for authenticated attackers, with Subscribe...
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.1
- Disclosed:
- Oct 23, 2025
CVE-2025-11128 on NVD →
Feedzy RSS Feeds Lite <= 5.1.0 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds' function. This makes it possible for authenticated attackers, with Subscriber-lev...
- CVSS:
- 5
- Affected:
- up to 5.1.0
- Fixed in:
- 5.1.1
- Disclosed:
- Oct 22, 2025
CVE-2025-11128 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.8 (closed)
unknown
[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 4.4.7 via the fetch_feed functionality. This makes it possible for authenticated attackers, with contributor...
- Affected:
- up to 4.4.8
- Fixed in:
- 4.4.8
- Disclosed:
- Apr 17, 2024
CVE-2023-6805 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF)
medium
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 4.4.7 via the fetch_feed functionality. This makes it possible for authenticated attackers, with contributor acce...
- CVSS:
- 6.4
- Affected:
- up to 4.4.7
- Fixed in:
- 4.4.8
- Disclosed:
- Apr 16, 2024
CVE-2023-6805 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.3.4 (closed)
unknown
[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping on the Content-Type...
- Affected:
- up to 4.3.4
- Fixed in:
- 4.3.4
- Disclosed:
- Apr 7, 2024
CVE-2023-6877 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error Message
medium
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping on the Content-Type fiel...
- CVSS:
- 6.4
- Affected:
- up to 4.3.3
- Fixed in:
- 4.3.4
- Disclosed:
- Apr 6, 2024
CVE-2023-6877 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.3 (closed)
unknown
[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'feedzy_wizard_step_process' and 'import_status' functions in all versions up to, and including, 4.4.2. T...
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.3
- Disclosed:
- Feb 20, 2024
CVE-2024-1318 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.3 (closed)
unknown
[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection via the ‘search_key’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparat...
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.3
- Disclosed:
- Feb 20, 2024
CVE-2024-1317 on NVD →
RSS Aggregator by Feedzy <= 4.4.2 - Authenticated(Contributor+) SQL Injection
high
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection via the ‘search_key’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o...
- CVSS:
- 8.8
- Affected:
- up to 4.4.2
- Fixed in:
- 4.4.3
- Disclosed:
- Feb 9, 2024
CVE-2024-1317 on NVD →
RSS Aggregator by Feedzy <= 4.4.2 - Missing Authorization to Arbitrary Page Creation and Publication
medium
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'feedzy_wizard_step_process' and 'import_status' functions in all versions up to, and including, 4.4.2. This m...
- CVSS:
- 6.5
- Affected:
- up to 4.4.2
- Fixed in:
- 4.4.3
- Disclosed:
- Feb 9, 2024
CVE-2024-1318 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.2 (closed)
unknown
[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and including, 4.4.1. This makes it possible for authenticated attac...
- Affected:
- up to 4.4.2
- Fixed in:
- 4.4.2
- Disclosed:
- Feb 5, 2024
CVE-2024-1092 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing Authorization
medium
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers,...
- CVSS:
- 4.3
- Affected:
- up to 4.4.1
- Fixed in:
- 4.4.2
- Disclosed:
- Feb 2, 2024
CVE-2024-1092 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.2 (closed)
unknown
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers,...
- Affected:
- up to 4.4.2
- Fixed in:
- 4.4.2
- Disclosed:
- Feb 2, 2024
ThemeIsle SDK <= Various Versions - Missing Authorization
medium
Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to update options values that allow ThemeIsle to track...
- CVSS:
- 5.3
- Affected:
- up to 4.4.1
- Fixed in:
- 4.4.2
- Disclosed:
- Feb 1, 2024
CVE-2024-1047 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.3.3 (closed)
unknown
[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for au...
- Affected:
- up to 4.3.3
- Fixed in:
- 4.3.3
- Disclosed:
- Jan 6, 2024
CVE-2023-6801 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.3.3 (closed)
unknown
[en] The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check when updating settings in all versions up to, and including, 4.3.2. This makes it possible for authenticated attacker...
- Affected:
- up to 4.3.3
- Fixed in:
- 4.3.3
- Disclosed:
- Jan 6, 2024
CVE-2023-6798 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authent...
- CVSS:
- 6.4
- Affected:
- up to 4.3.2
- Fixed in:
- 4.3.3
- Disclosed:
- Jan 5, 2024
CVE-2023-6801 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Missing Authorization
medium
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check when updating settings in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, wi...
- CVSS:
- 5.4
- Affected:
- up to 4.3.2
- Fixed in:
- 4.3.3
- Disclosed:
- Jan 5, 2024
CVE-2023-6798 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 3.4.3 (closed)
unknown
[en] The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it possible for unauthenticated attackers to update post meta via a fo...
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Oct 20, 2023
CVE-2020-36758 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 3.4.3 (closed)
unknown
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.1.1 (closed)
unknown
[en] The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such a...
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Jan 30, 2023
CVE-2022-4667 on NVD →
RSS Aggregator by Feedzy <= 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor l...
- CVSS:
- 6.4
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.1
- Disclosed:
- Jan 4, 2023
CVE-2022-4667 on NVD →
RSS Aggregator by Feedzy <= 3.4.2 - Cross-Site Request Forgery Bypass
medium
The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it possible for unauthenticated attackers to update post meta via a forged...
- CVSS:
- 4.3
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Sep 16, 2020
CVE-2020-36758 on NVD →
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 3.4.3 (closed)
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress RSS Aggregator by Feedzy plugin (versions <= 3.4.2).
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Sep 16, 2020
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 3.4.3 (closed)
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3