PT-2024-16641 · WordPress · The Rss Aggregator By Feedzy – Feed To Post

Muhammad Daffa

·

Published

2024-02-05

·

Updated

2024-02-13

·

CVE-2024-1092

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress versions up to, and including, 4.4.1
Description The issue allows authenticated attackers with contributor access or higher to create, edit, or delete feed categories created by them due to a missing capability check on the feedzy dashboard.
Recommendations For versions up to, and including, 4.4.1, update to a version higher than 4.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the feedzy dashboard to minimize the risk of exploitation.

Fix

Improper Access Control

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-1092

Affected Products

The Rss Aggregator By Feedzy – Feed To Post