Authorization Bypass in RSS Aggregator Plugin for WordPress by Feedzy
CVE-2026-8976
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 5 June 2026
What is CVE-2026-8976?
The RSS Aggregator by Feedzy plugin for WordPress is susceptible to an authorization bypass that allows authenticated users with contributor-level access or higher to execute unauthorized actions. This vulnerability stems from the plugin's failure to adequately verify user permissions, enabling attackers to create and manage RSS import jobs, delete associated posts, clear import error logs, and access taxonomy terms and post meta_key names. A nonce exploited through the feedzyjs script grants contributors access to sensitive functions without the need for additional privilege escalation.
Affected Version(s)
RSS Aggregator by Feedzy β Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator 0 <= 5.1.7