Junglewise Threat Intelligence

CVE-2026-66437: Themeisle Feedzy RSS Feeds SSRF in WordPress plugin

CVE-2026-66437 · Severity: medium · CVSS 4.9 · Published 2026-07-27

Vendors: Themeisle.

Executive brief

Themeisle Feedzy RSS Feeds, a popular WordPress plugin used to aggregate and display RSS feeds, is vulnerable to a security flaw that could allow users with 'Contributor' level access to make the server perform unauthorized web requests. An attacker could use this to probe internal network services or access sensitive information that is not intended to be public. While the risk is considered medium, organizations should update the plugin to prevent internal network reconnaissance.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Themeisle Feedzy RSS Feeds plugin for WordPress (versions <= 5.2.4). The flaw allows an authenticated attacker with Contributor-level permissions or higher to induce the server to make requests to arbitrary domains or internal network resources. This is classified under CWE-918 and typically occurs due to insufficient validation of user-supplied URLs used in feed processing. An attacker can leverage this to perform internal port scanning or access metadata services in cloud environments. The issue is addressed in version 5.2.5.

Affected products

  • Themeisle Feedzy RSS Feeds <= 5.2.4

Timeline

  • 2026-07-14: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-27: advisory: NVD and Patchstack published advisory details
  • 2026-07-27: patched: Fixed in version 5.2.5

References