Impact
The vulnerability resides in the Feedzy RSS Feeds WordPress plugin, specifically in versions 5.2.4 and older. It allows an attacker to craft requests that cause the plugin to fetch arbitrary URLs on behalf of the server. This could enable the exfiltration of internal resources, the discovery of other services, or the execution of internal network requests that would otherwise be blocked. The weakness corresponds to CWE‑918, signifying improper handling of user-supplied URLs.
Affected Systems
The affected product is the Feedzy plugin developed by Themeisle. All installations of Feedzy up to and including version 5.2.4 are vulnerable; the fix is available in version 5.2.5 and later.
Risk and Exploitability
The CVSS score of 4.9 places this issue in the moderate range, indicating that while exploitation is feasible, it may not lead to immediate critical damage without appropriate context. The EPSS score of < 1% indicates only a very low likelihood of exploitation. The issue is not included in the CISA KEV catalogue. Attackers who can influence the Feedzy feed URL field may exploit this vulnerability to force the target server into making sub‑network requests, potentially accessing internal data or services.
OpenCVE Enrichment