Server Side Request Forgery Vulnerability in Feedzy Plugin by WordPress
CVE-2026-66437
4.9MEDIUM
What is CVE-2026-66437?
The Feedzy plugin for WordPress has a vulnerability that exposes it to Server Side Request Forgery (SSRF) attacks in versions 5.2.4 and earlier. This vulnerability can allow attackers to send requests to unauthorized internal resources, potentially leading to data leakage or other security issues. Users are advised to upgrade to the latest version of the plugin to mitigate any risks associated with this vulnerability.
Affected Version(s)
Feedzy <= 5.2.4
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program