CVE · Medium

CVE-2024-1318 — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1318 RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.4.3 Missing Authorization Medium 6.5 < 4.4.3 4.4.3 2024-02-09

CVE-2024-1318

The WordPress RSS Aggregator by Feedzy plugin before version 4.4.3 contains a broken access control vulnerability that was discovered by Lucio Sá. The flaw stems from inadequate authorization checks in a function, allowing unauthenticated or low-privilege users to perform actions restricted to higher-privilege accounts. This weakness has been remedied in version 4.4.3 and later releases.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.