WordPress security by component
Feedzy
Plugin description
Feedzy is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
feedzy-rss-feedsLatest vulnerability
CVE-2026-66437: Feedzy contributors can trigger server-side request forgery
Feedzy through 5.2.4 lets a Contributor supply a destination that reaches an undisclosed server-side fetch operation. This can make the WordPress server send requests to attacker-selected or internal resources. The Patchstack CNA record does not disclose the route, action, URL parameter, fetch function, allowed schemes or response visibility.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-66437
Feedzy contributors can trigger server-side request forgery
Feedzy through 5.2.4 lets a Contributor supply a destination that reaches an undisclosed server-side fetch operation. This can make the WordPress server send requests to attacker-selected or internal resources. The Patchstack CNA record does not disclose the route, action, URL parameter, fetch function, allowed schemes or response visibility.
|
5.2.5 |
CVE4.9
NVDPending
|
| Jul 02, 2026 |
CVE-2026-13252
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator: Cross-site scripting
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.2.1.
|
> 5.2.1 |
CVE6.4
NVDPending
|
| Jun 06, 2026 |
CVE-2026-8976
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator: A security weakness
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.1.7.
|
> 5.1.7 |
CVE4.3
NVDPending
|
| Dec 11, 2025 |
CVE-2025-11467
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator: Server-side request forgery
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE5.8
NVDPending
|
| Oct 23, 2025 |
CVE-2025-11128
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator: Server-side request forgery
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator is affected by server-side request forgery. Exploitation requires at least subscriber-level access. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE5.0
NVDPending
|
| Feb 29, 2024 |
CVE-2024-1318
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator: A security weakness
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 29, 2024 |
CVE-2024-1317
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator: SQL injection
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVDPending
|