Stored Cross-Site Scripting Vulnerability in RSS Aggregator by Feedzy for WordPress
CVE-2026-13252

6.4MEDIUM

What is CVE-2026-13252?

The RSS Aggregator by Feedzy allows for stored cross-site scripting (XSS) vulnerabilities due to inadequate input sanitization and output escaping. This security flaw affects all versions up to 5.2.1, letting authenticated attackers with contributor-level access inject malicious scripts into web pages. These scripts execute when users access the compromised pages, leading to potential data breaches or other malicious activities.

Affected Version(s)

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator 0 <= 5.2.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PRISM
.