CVE-2025-11467
- EPSS 0.08%
- Veröffentlicht 11.12.2025 01:55:32
- Zuletzt bearbeitet 15.04.2026 00:35:42
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 5.1.1 via the feedzy_lazy_load function. Th...
- EPSS 0.05%
- Veröffentlicht 23.10.2025 12:32:32
- Zuletzt bearbeitet 15.04.2026 00:35:42
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds' function. T...
CVE-2023-6805
- EPSS 0.28%
- Veröffentlicht 17.04.2024 13:15:08
- Zuletzt bearbeitet 08.04.2026 18:18:42
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 4.4.7 via the fetch_feed functionality. Thi...
CVE-2023-6877
- EPSS 0.66%
- Veröffentlicht 07.04.2024 02:15:07
- Zuletzt bearbeitet 08.04.2026 18:18:44
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3.3 due to insuff...
CVE-2024-1317
- EPSS 0.43%
- Veröffentlicht 29.02.2024 01:43:47
- Zuletzt bearbeitet 08.04.2026 19:20:36
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection via the ‘search_key’ parameter in all versions up to, and including, 4.4.2 due to insufficient escapi...
CVE-2024-1318
- EPSS 0.17%
- Veröffentlicht 29.02.2024 01:43:47
- Zuletzt bearbeitet 08.04.2026 17:18:17
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'feedzy_wizard_step_process' and 'import...
CVE-2024-1092
- EPSS 0.12%
- Veröffentlicht 05.02.2024 22:16:07
- Zuletzt bearbeitet 08.04.2026 18:20:26
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and...
CVE-2023-6801
- EPSS 0.08%
- Veröffentlicht 06.01.2024 10:15:46
- Zuletzt bearbeitet 08.04.2026 19:19:00
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.2 due to insufficient inpu...
CVE-2023-6798
- EPSS 0.08%
- Veröffentlicht 06.01.2024 10:15:45
- Zuletzt bearbeitet 08.04.2026 19:19:00
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check when updating settings in all versions up to, and in...
CVE-2020-36758
- EPSS 0.14%
- Veröffentlicht 20.10.2023 08:15:11
- Zuletzt bearbeitet 08.04.2026 19:17:38
The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it po...