Authorization Bypass in RSS Aggregator Plugin for WordPress by Feedzy
CVE-2026-8976

4.3MEDIUM

What is CVE-2026-8976?

The RSS Aggregator by Feedzy plugin for WordPress is susceptible to an authorization bypass that allows authenticated users with contributor-level access or higher to execute unauthorized actions. This vulnerability stems from the plugin's failure to adequately verify user permissions, enabling attackers to create and manage RSS import jobs, delete associated posts, clear import error logs, and access taxonomy terms and post meta_key names. A nonce exploited through the feedzyjs script grants contributors access to sensitive functions without the need for additional privilege escalation.

Affected Version(s)

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator 0 <= 5.1.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jack Pas
.