Impact
The Private Feed Key WordPress plugin allows any attacker to authenticate a feed request with an arbitrary key because the plugin does not verify that the key was issued by the system. This flaw enables unauthenticated attackers to obtain login credentials for any user, including administrators, thereby granting full control of the site.
Affected Systems
WordPress sites running the Private Feed Key plugin version 0.1 or earlier are vulnerable. The issue applies to all installations that have not yet updated beyond version 0.1.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating a critical risk. Its EPSS score is below 1%, suggesting a low exploitation likelihood at the time of analysis; it is not listed in the CISA KEV catalog. The most likely attack vector is an unauthenticated attacker sending a feed request that includes a forged 'feedkey' parameter, which is then accepted by the plugin as a valid authentication.
OpenCVE Enrichment