Impact
The RSS Aggregator by Feedzy plugin fails to verify that a requester owns or is allowed to edit an import job named in the request. As a result, users with author-level access and above can permanently delete posts created by another user's import job, reset its deduplication and scheduling state, disable the job, or clear its error log. One affected action performs no object‑type check, enabling the unpublished of arbitrary posts and pages regardless of who owns them. This flaw allows an attacker to alter or destroy other users’ content and disrupt scheduled imports, causing loss of data integrity and availability.
Affected Systems
The vulnerability affects the WordPress plugin RSS Aggregator by Feedzy on all releases older than 5.2.6. Any WordPress installation using the plugin version 5.2.5 or earlier is susceptible. No other vendor or product is listed.
Risk and Exploitability
The flaw can be exploited by sending requests to the plugin’s endpoints that require author or higher privileges, a level of access that many WordPress sites grant to editors and authors. While no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the lack of ownership checks indicates a non‑trivial likelihood of exploitation, especially on sites with multiple authors. The impact gives an attacker the ability to modify or delete content and pause or reset import jobs, potentially causing significant disruption.
OpenCVE Enrichment