The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 5.1.1 via the feedzy_lazy_load function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themeisle
Themeisle rss Aggregator By Feedzy Wordpress Wordpress wordpress |
|
| Vendors & Products |
Themeisle
Themeisle rss Aggregator By Feedzy Wordpress Wordpress wordpress |
Thu, 11 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Dec 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 5.1.1 via the feedzy_lazy_load function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. | |
| Title | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated Blind Server-Side Request Forgery | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-12-11T01:55:32.407Z
Updated: 2025-12-11T15:34:28.633Z
Reserved: 2025-10-07T20:51:21.871Z
Link: CVE-2025-11467
Updated: 2025-12-11T15:34:26.447Z
Status : Awaiting Analysis
Published: 2025-12-11T03:15:57.450
Modified: 2025-12-12T15:18:13.390
Link: CVE-2025-11467
No data.