CVE

CVE-2026-18934 — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.2.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-18934 RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.2.6 Incorrect Authorization Unknown < 5.2.6 5.2.6 2026-07-27

CVE-2026-18934

The RSS Aggregator by Feedzy WordPress plugin has a vulnerability that allows users with author-level access or higher to manipulate import jobs and posts created by other users. Specifically, they can delete posts, reset the job's state, disable the job, or clear its error log, regardless of who originally created the job. Additionally, this vulnerability allows users to unpublish arbitrary posts and pages, regardless of ownership.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.