Description
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query information from internal services.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
* (semver)
Timeline
| 2025-09-27: | Vendor Notified |
| 2025-10-22: | Disclosed |
Credits
Lucas Montes
References
www.wordfence.com/...-3e83-425a-9f0f-5e529be15e05?source=cve
plugins.trac.wordpress.org/...-rss-feeds-gutenberg-block.php
plugins.trac.wordpress.org/...-rss-feeds-gutenberg-block.php
plugins.trac.wordpress.org/...-rss-feeds-gutenberg-block.php
plugins.trac.wordpress.org/...-rss-feeds-gutenberg-block.php
plugins.trac.wordpress.org/changeset/3378828/