PT-2025-39714 · WordPress · Sync Feedly

Nabil Irawan

·

Published

2025-09-27

·

Updated

2025-09-27

·

CVE-2025-9894

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sync Feedly plugin for WordPress versions prior to 1.0.2
Description The software is susceptible to a Cross-Site Request Forgery issue. This is due to a lack of proper nonce validation within the crsf cron job func function. An unauthenticated attacker could potentially trigger content synchronization from Feedly, which may lead to the creation of multiple posts if they can trick a site administrator into performing an action, such as clicking a link.
Recommendations Update the Sync Feedly plugin to version 1.0.2 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-9894

Affected Products

Sync Feedly