CVE-2026-104735
Received Received - Intake

Stored XSS in Feedzy WordPress Plugin via RSS Feed Title

Vulnerability report for CVE-2026-104735, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Feedzy Loop Block Feed URL / RSS <title> in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is not neutralized at save time because post_content stores only a benign block reference to an external feed URL; the malicious HTML is injected at render time from the attacker-controlled RSS feed title, bypassing any save-time wp_kses filtering.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
themeisle RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Stored Cross-Site Scripting (XSS) issue in the RSS Aggregator by Feedzy WordPress plugin. It allows authenticated attackers with contributor-level access or higher to inject malicious scripts into web pages via the Feedzy Loop Block Feed URL or RSS title. The injected scripts execute when users access the affected pages because the malicious HTML is rendered from an attacker-controlled RSS feed at runtime, bypassing WordPress's save-time filtering.

Detection Guidance

This vulnerability is specific to the WordPress RSS Aggregator by Feedzy plugin. To detect it, check if your WordPress site uses the vulnerable version (up to 5.2.10). Inspect pages using the Feedzy Loop Block for unexpected scripts in feed titles. No direct network commands are provided in the context.

Impact Analysis

An attacker could steal user sessions, redirect users to malicious sites, or perform actions on their behalf. This could lead to unauthorized data access, defacement of websites, or spreading malware. Users with contributor-level access or higher could exploit this to compromise the site and its visitors.

Compliance Impact

This vulnerability could lead to data breaches, exposing user data and violating GDPR or HIPAA requirements. If exploited, it may result in unauthorized access to personal or sensitive information, leading to legal penalties, reputational damage, and loss of compliance certifications.

Mitigation Strategies

Update the Feedzy plugin to version 5.2.11 or later immediately. Remove or restrict contributor-level access to untrusted users. Review pages using the Feedzy Loop Block for injected scripts and clean them manually if affected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104735. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart