CVE · Medium

CVE-2024-1092 — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1092 RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.2 Improper Access Control Medium 4.3 < 4.4.2 4.4.2 2024-02-02

CVE-2024-1092

The WordPress RSS Aggregator by Feedzy plugin before version 4.4.2 contains a broken access control flaw that fails to properly verify user permissions or authentication tokens before allowing certain actions to execute. This gap in authorization checks allows unauthenticated or low-privilege users to perform functions that should be restricted to higher-privilege accounts. The vulnerability has been patched in version 4.4.2 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.