Impact
The Feedzy RSS Aggregator plugin allows authenticated users with contributor privileges to inject malicious scripts into the RSS <title> field of external feeds. Because the plugin stores a block reference but does not sanitize or escape this field when rendering the page, the injected code executes in the browsers of any visitor to the infected page, enabling theft of session cookies, credential phishing, or defacement. The vulnerability is a classic stored XSS flaw (CWE‑79).
Affected Systems
WordPress sites running the Feedzy RSS Feeds plugin version 5.2.10 or earlier, developed by ThemeIsle under the product name RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. EPSS information is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. Exfiltration of data or defacement requires that the attacker controls a feed source and has contributor‑level access. Once the malicious feed is rendered, any site visitor’s browser will execute the payload. The attack vector is therefore authenticated and relies on user role, but the impact spans all site users who view the affected block.
OpenCVE Enrichment