← WordPress Vulnerabilities
WordPress security by component

Feedzy

Feedzy is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: feedzy-rss-feeds

CVE-2026-66437: Feedzy contributors can trigger server-side request forgery

Feedzy through 5.2.4 lets a Contributor supply a destination that reaches an undisclosed server-side fetch operation. This can make the WordPress server send requests to attacker-selected or internal resources. The Patchstack CNA record does not disclose the route, action, URL parameter, fetch function, allowed schemes or response visibility.

PublishedJul 27, 2026
Known safe version5.2.5
Safe version
Jul 27, 2026 CVE-2026-66437
Feedzy contributors can trigger server-side request forgery
Feedzy through 5.2.4 lets a Contributor supply a destination that reaches an undisclosed server-side fetch operation. This can make the WordPress server send requests to attacker-selected or internal resources. The Patchstack CNA record does not disclose the route, action, URL parameter, fetch function, allowed schemes or response visibility.
5.2.5
CVE4.9
NVDPending
Jul 02, 2026 CVE-2026-13252
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator: Cross-site scripting
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.2.1.
> 5.2.1
CVE6.4
NVDPending
Jun 06, 2026 CVE-2026-8976
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator: A security weakness
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.1.7.
> 5.1.7
CVE4.3
NVDPending
Dec 11, 2025 CVE-2025-11467
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator: Server-side request forgery
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE5.8
NVDPending
Oct 23, 2025 CVE-2025-11128
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator: Server-side request forgery
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator is affected by server-side request forgery. Exploitation requires at least subscriber-level access. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE5.0
NVDPending
Feb 29, 2024 CVE-2024-1318
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator: A security weakness
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Feb 29, 2024 CVE-2024-1317
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator: SQL injection
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVDPending