Vulnerability in RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator — CVE-2026-104735
What to do now
Update RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator to 5.2.11 or later.
Affected versions
- Everything up to and including 5.2.10
Affected: RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator (plugin, feedzy-rss-feeds)
What the vulnerability is
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Feedzy Loop Block Feed URL / RSS <title> in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is not neutralized at save time because post_content stores only a benign block reference to an external feed URL; the malicious HTML is injected at render time from the attacker-controlled RSS feed title, bypassing any save-time wp_kses filtering.