The WordPress plugin Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator (also known as the RSS Aggregator) has a security vulnerability that affects all versions up to version 4.3.2. This vulnerability allows attackers who have author-level permissions or higher to inject malicious code into pages that will run whenever a user visits the page. This happens because the plugin does not properly check input or prevent the malicious code from running.