Stored Cross-Site Scripting Vulnerability in RSS Aggregator by Feedzy for WordPress
CVE-2026-13252
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 2 July 2026
What is CVE-2026-13252?
The RSS Aggregator by Feedzy allows for stored cross-site scripting (XSS) vulnerabilities due to inadequate input sanitization and output escaping. This security flaw affects all versions up to 5.2.1, letting authenticated attackers with contributor-level access inject malicious scripts into web pages. These scripts execute when users access the compromised pages, leading to potential data breaches or other malicious activities.
Affected Version(s)
RSS Aggregator by Feedzy β Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator 0 <= 5.2.1