Extension WordPress

Vulnérabilités RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

Cette page rassemble les failles publiées pour RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
0Critiques
14Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

14 fiches

CVE-2026-13252 Moyenne · 6,4
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

RSS Aggregator by Feedzy <= 5.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'aspectRatio' Attribute in all versions up to, and including, 5.2.1 due to…

Versions affectées

*-5.2.1

Correctif

5.2.2

Publication

01/07/2026

CVE-2026-8976 Moyenne · 4,3
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

RSS Aggregator by Feedzy <= 5.1.7 – Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-Actions

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.7. This is due to the plugin…

Versions affectées

*-5.1.7

Correctif

5.1.8

Publication

05/06/2026

CVE-2025-11467 Moyenne · 5,8
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 – Unauthenticated Blind Server-Side Request Forgery

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 5.1.1 via the feedzy_lazy_load function.…

Versions affectées

*-5.1.1

Correctif

5.1.2

Publication

10/12/2025

CVE-2025-11128 Moyenne · 5,0
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

Feedzy RSS Feeds Lite <= 5.1.0 – Authenticated (Subscriber+) Server-Side Request Forgery

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds' function. This…

Versions affectées

*-5.1.0

Correctif

5.1.1

Publication

22/10/2025

CVE-2023-6805 Moyenne · 6,4
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 – Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF)

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 4.4.7 via the fetch_feed functionality.…

Versions affectées

*-4.4.7

Correctif

4.4.8

Publication

16/04/2024

CVE-2023-6877 Moyenne · 6,4
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error Message

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3.3 due…

Versions affectées

*-4.3.3

Correctif

4.3.4

Publication

06/04/2024

CVE-2024-1317 Élevée · 8,8
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

RSS Aggregator by Feedzy <= 4.4.2 – Authenticated(Contributor+) SQL Injection

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection via the ‘search_key’ parameter in all versions up to, and including, 4.4.2 due to…

Versions affectées

*-4.4.2

Correctif

4.4.3

Publication

09/02/2024

CVE-2024-1318 Moyenne · 6,5
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

RSS Aggregator by Feedzy <= 4.4.2 – Missing Authorization to Arbitrary Page Creation and Publication

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'feedzy_wizard_step_process' and 'import_status' functions…

Versions affectées

*-4.4.2

Correctif

4.4.3

Publication

09/02/2024

CVE-2024-1092 Moyenne · 4,3
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 – Missing Authorization

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions…

Versions affectées

*-4.4.1

Correctif

4.4.2

Publication

02/02/2024

CVE-2024-1047 Moyenne · 5,3
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

ThemeIsle SDK <= Various Versions – Missing Authorization

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to…

Versions affectées

*-4.4.1

Correctif

4.4.2

Publication

01/02/2024

CVE-2023-6798 Moyenne · 5,4
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 – Missing Authorization

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check when updating settings in all versions up…

Versions affectées

*-4.3.2

Correctif

4.3.3

Publication

05/01/2024

CVE-2023-6801 Moyenne · 6,4
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 – Authenticated (Author+) Stored Cross-Site Scripting

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.2 due to…

Versions affectées

*-4.3.2

Correctif

4.3.3

Publication

05/01/2024

CVE-2022-4667 Moyenne · 6,4
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

RSS Aggregator by Feedzy <= 4.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This…

Versions affectées

*-4.1.0

Correctif

4.1.1

Publication

04/01/2023

CVE-2020-36758 Moyenne · 4,3
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

RSS Aggregator by Feedzy <= 3.4.2 – Cross-Site Request Forgery Bypass

The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it possible…

Versions affectées

[*, 3.4.3)

Correctif

3.4.3

Publication

16/09/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités