Missing Authorization Vulnerability in RSS Feed Widget by Fahad Mahmood
CVE-2025-69349
5.4MEDIUM
What is CVE-2025-69349?
The RSS Feed Widget by Fahad Mahmood is vulnerable due to a missing authorization flaw that allows attackers to exploit incorrectly configured access control security levels. This vulnerability primarily affects versions from n/a to 3.0.2, posing a risk to users who have not updated their plugins. Malicious actors could potentially gain unauthorized access to restricted functionalities, emphasizing the necessity of maintaining updated security measures to protect sensitive data.
Affected Version(s)
RSS Feed Widget 0 <= 3.0.2