Executive brief
The Feedzy RSS Aggregator plugin for WordPress, which is used to automatically import and display content from RSS feeds and YouTube, is vulnerable to a security flaw. An attacker with contributor-level access can inject malicious scripts into website pages. When other users or administrators visit these pages, the scripts will execute, potentially leading to unauthorized actions or data theft.
Technical details
The Feedzy RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping of the 'aspectRatio' attribute. This vulnerability allows authenticated attackers with contributor-level permissions or higher to inject arbitrary web scripts into pages. Because the scripts are stored on the server, they will execute in the browser of any user who visits the affected page. The issue exists in all versions up to and including 5.2.1. A patch appears to be available in subsequent versions based on the provided changeset references.
Affected products
- ThemeIsle RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator up to, and including, 5.2.1
Timeline
- 2026-07-02: disclosed
- 2026-07-02: advisory
References
- https://plugins.trac.wordpress.org/browser/feedzy-rss-feeds/tags/5.2.0/includes/abstract/feedzy-rss-feeds-admin-abstract.php
- https://plugins.trac.wordpress.org/browser/feedzy-rss-feeds/tags/5.2.0/includes/abstract/feedzy-rss-feeds-admin-abstract.php
- https://plugins.trac.wordpress.org/browser/feedzy-rss-feeds/tags/5.2.0/includes/abstract/feedzy-rss-feeds-admin-abstract.php
- https://plugins.trac.wordpress.org/browser/feedzy-rss-feeds/tags/5.2.0/includes/abstract/feedzy-rss-feeds-admin-abstract.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3586919%40feedzy-rss-feeds&new=3586919%40feedzy-rss-feeds&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d402b7d1-3c12-4bdd-8ff3-e58d5501f0c0?source=cve