Access violation vulnerability in RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator 4.4.2

The RSS Aggregator plugin for WordPress, called Feedzy, has a security issue that could allow unauthorized changes to be made to the data. This is because there is a missing check in the ‘feedzy_wizard_step_process’ and ‘import_status’ functions in all versions up to 4.4.2. This means that someone who is logged in and has Contributor access or higher, which usually only allows them to create posts and not pages, could create and publish posts with any content they want.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.