The RSS Aggregator plugin for WordPress, called Feedzy, has a security issue that could allow unauthorized changes to be made to the data. This is because there is a missing check in the ‘feedzy_wizard_step_process’ and ‘import_status’ functions in all versions up to 4.4.2. This means that someone who is logged in and has Contributor access or higher, which usually only allows them to create posts and not pages, could create and publish posts with any content they want.