Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total7
Critical0
High1
Medium6
Reset
Showing 1-7 of 7 records
Threat Entry Updated 2025-01-14

CVE-2023-6805 - Rss Aggregator By Feedzy Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 4.4.7 via the fetch_feed functionality. This makes it possible for authenticated attackers, with contributor access and above, to make web requests to arbitrary locations originating from the web application and can be used to modify information from internal services. NOTE: This vulnerability, exploitable by contributor-level users, was was fixed in version 4.4.7. The same vulnerability was fixed…

PLUGIN Rss Aggregator By Feedzy

CVE-2023-6805

MEDIUM CVSS 6.4 2024-04-17
Threat Entry Updated 2025-01-14

CVE-2023-6877 - Rss Aggregator By Feedzy Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping on the Content-Type field of error messages when retrieving an invalid RSS feed. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rss Aggregator By Feedzy

CVE-2023-6877

MEDIUM CVSS 6.4 2024-04-07
Threat Entry Updated 2024-12-31

CVE-2024-1317 - Rss Aggregator By Feedzy Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection via the ‘search_key’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Rss Aggregator By Feedzy

CVE-2024-1317

HIGH CVSS 8.8 2024-02-29
Threat Entry Updated 2024-12-31

CVE-2024-1318 - Rss Aggregator By Feedzy Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'feedzy_wizard_step_process' and 'import_status' functions in all versions up to, and including, 4.4.2. This makes it possible for authenticated attackers, with Contributor access and above, who are normally restricted to only being able to create posts rather than pages, to draft and publish posts with arbitrary content.

PLUGIN Rss Aggregator By Feedzy

CVE-2024-1318

MEDIUM CVSS 6.5 2024-02-29
Threat Entry Updated 2024-11-21

CVE-2024-1092 - Rss Aggregator By Feedzy Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers, with contributor access or higher, to create, edit or delete feed categories created by them.

PLUGIN Rss Aggregator By Feedzy

CVE-2024-1092

MEDIUM CVSS 4.3 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2023-6801 - Rss Aggregator By Feedzy Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Rss Aggregator By Feedzy

CVE-2023-6801

MEDIUM CVSS 6.4 2024-01-06
Threat Entry Updated 2024-11-21

CVE-2023-6798 - Rss Aggregator By Feedzy Plugin

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check when updating settings in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with author-level access or above to change the plugin's settings including proxy settings, which are also exposed to authors.

PLUGIN Rss Aggregator By Feedzy

CVE-2023-6798

MEDIUM CVSS 5.4 2024-01-06
Scroll to top