CVE-2026-8976
The Feedzy plugin for WordPress has a security flaw that allows authorized attackers with contributor-level access or higher to perform certain actions without proper permission. This is because the plugin doesn't properly check if a user is allowed to take these actions, allowing them to create and execute RSS import jobs, delete posts associated with these jobs, clear error logs, and view certain metadata, all without needing a special exploit. The necessary security tokens for these actions are inadvertently made available to users with the ability to edit posts, making it easier for attackers to exploit this vulnerability.
Based on public CVE data (MITRE/NVD).