CVE-2026-18934
Received Received - Intake

Unauthenticated Post Deletion in Feedzy RSS Aggregator

Vulnerability report for CVE-2026-18934, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: WPScan

Description

The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowing users with author-level access and above to permanently delete the posts created by another user's import job, reset its deduplication and scheduling state, disable it, or clear its error log. One of the affected actions performs no object-type check either, so arbitrary posts and pages can also be unpublished regardless of who owns them.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
feedzy rss_aggregator to 5.2.6 (exc)
feedzy the_rss_aggregator to 5.2.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the RSS Aggregator by Feedzy WordPress plugin before version 5.2.6 allows users with author-level access or higher to manipulate import jobs created by other users. Attackers can delete posts from another user's import job, reset its settings, disable the job, or clear its error logs. One action also lacks proper checks, letting unauthorized users unpublish any posts or pages.

Detection Guidance

Check the installed version of the Feedzy RSS Aggregator plugin. If it is below 5.2.6, the system is vulnerable. Use WordPress admin panel or run a command like 'wp plugin list' in the WordPress directory to verify the version.

Impact Analysis

If exploited, this flaw could lead to unauthorized deletion of content, disruption of scheduled imports, loss of data integrity, and unintended changes to website visibility. Users with author-level access could misuse this to affect other users' work or the overall site functionality.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling unauthorized users to delete, modify, or unpublish posts and pages, potentially leading to unauthorized data exposure or loss of integrity. Improper access controls may violate requirements for data protection and access management.

Mitigation Strategies

Update the Feedzy RSS Aggregator plugin to version 5.2.6 or later immediately. Remove unnecessary author-level user accounts and review user permissions to ensure least privilege access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18934. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart