CVE · High

CVE-2024-1317 — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1317 RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 4.4.3 4.4.3 2024-02-09

CVE-2024-1317

The Feedzy RSS Aggregator plugin for WordPress before version 4.4.3 contains a SQL injection vulnerability in the 'search_key' parameter, which is not properly escaped or prepared in database queries. Authenticated users with contributor-level permissions or higher can exploit this flaw to inject additional SQL commands and access sensitive data stored in the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.