CVE · Medium

CVE-2025-11467 — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.1.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11467 RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.1.2 Server-Side Request Forgery (SSRF) Medium 5.8 < 5.1.2 5.1.2 2025-12-10

CVE-2025-11467

The Feedzy plugin for WordPress contains a flaw in its feed processing mechanism, allowing unauthorized users to initiate server-side requests to external sites without authentication. This vulnerability is present in all versions up to 5.1.1, where the feedzy_lazy_load function can be exploited to access internal services and manipulate data. As a result, attackers can potentially query or modify sensitive information within these services.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.