Description
WordPress Plugin RSS Aggregator by Feedzy-Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently draft and publish posts with arbitrary content. WordPress Plugin RSS Aggregator by Feedzy-Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator version 4.4.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.4.3 or latest
References
Related Vulnerabilities
WordPress Plugin WP Visitor Statistics (Real Time Traffic) SQL Injection (4.7)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2022-37454)
WordPress Plugin WP Login Security and History Cross-Site Request Forgery (1.0)
Telerik Web UI Inadequate Encryption Strength Vulnerability (CVE-2017-11317)