Impact
The WP Filter & Combine RSS Feeds plugin’s internal post_listing_page function lacks a capability check, enabling any authenticated user with Contributor level access or higher to delete RSS feeds. This flaw does not allow code execution or privilege escalation, but it permits removal of user‑published feed content and disrupts content distribution, reducing site integrity.
Affected Systems
WordPress sites that have installed the evigeo WP Filter & Combine RSS Feeds plugin version 0.4 or earlier are impacted; the issue is independent of the WordPress core version as long as the vulnerable plugin remains active.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3, indicating moderate severity, and an EPSS score below 1%, signifying a low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalogue. Exploitation requires simple authentication and existing Contributor or higher permissions, which are commonly granted on many sites. While the impact is limited to feed deletion rather than broader system compromise, the loss of RSS syndication can affect user engagement and content reach.
OpenCVE Enrichment
EUVD