CVE Database /
CVE-2026-18934
CVE
CVE-2026-18934 — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.2.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-18934
|
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.2.6 |
Incorrect Authorization |
Unknown
|
< 5.2.6
|
5.2.6 |
2026-07-27 |
—
|
CVE-2026-18934
The RSS Aggregator by Feedzy WordPress plugin has a vulnerability that allows users with author-level access or higher to manipulate import jobs and posts created by other users. Specifically, they can delete posts, reset the job's state, disable the job, or clear its error log, regardless of who originally created the job. Additionally, this vulnerability allows users to unpublish arbitrary posts and pages, regardless of ownership.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings