Cross-Site Request Forgery Vulnerability in Sync Feedly Plugin for WordPress
CVE-2025-9894
4.3MEDIUM
What is CVE-2025-9894?
The Sync Feedly plugin for WordPress is affected by a vulnerability that exposes the site to Cross-Site Request Forgery due to inadequate nonce validation. This allows unauthenticated attackers to initiate content synchronization with Feedly by tricking an administrator into clicking a malicious link. Attackers could leverage this flaw to create multiple unwanted posts on the affected website, thereby compromising the site's integrity and reliability.
Affected Version(s)
Sync Feedly * <= 1.0.1