Server Side Request Forgery Vulnerability in Feedzy Plugin by WordPress
CVE-2026-66437

4.9MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-66437?

The Feedzy plugin for WordPress has a vulnerability that exposes it to Server Side Request Forgery (SSRF) attacks in versions 5.2.4 and earlier. This vulnerability can allow attackers to send requests to unauthorized internal resources, potentially leading to data leakage or other security issues. Users are advised to upgrade to the latest version of the plugin to mitigate any risks associated with this vulnerability.

Affected Version(s)

Feedzy <= 5.2.4

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.