Description
The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
Published: 2026-09-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

The Private Feed Key WordPress plugin allows any attacker to authenticate a feed request with an arbitrary key because the plugin does not verify that the key was issued by the system. This flaw enables unauthenticated attackers to obtain login credentials for any user, including administrators, thereby granting full control of the site.

Affected Systems

WordPress sites running the Private Feed Key plugin version 0.1 or earlier are vulnerable. The issue applies to all installations that have not yet updated beyond version 0.1.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.8, indicating a critical risk. Its EPSS score is below 1%, suggesting a low exploitation likelihood at the time of analysis; it is not listed in the CISA KEV catalog. The most likely attack vector is an unauthenticated attacker sending a feed request that includes a forged 'feedkey' parameter, which is then accepted by the plugin as a valid authentication.

Generated by OpenCVE AI on September 18, 2026 at 01:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Private Feed Key plugin to the latest available version, ensuring that the authentication mechanism properly verifies issued keys.
  • If an update is unavailable, uninstall or disable the plugin to eliminate the authentication bypass risk.
  • Restrict access to the feed endpoint, or implement additional authentication checks (e.g., IP whitelisting, two‑factor authentication) to mitigate the potential for unauthorized access.

Generated by OpenCVE AI on September 18, 2026 at 01:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
Title Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:29:59.333Z

Reserved: 2026-09-08T10:54:57.037Z

Link: CVE-2026-86707

cve-icon Vulnrichment

Updated: 2026-09-17T12:13:00.791Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:51.213

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-86707

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:00:16Z

Weaknesses