What this page helps you verify fast
This hub clusters every indexed record for FeedWordPress so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin FeedWordPress (`feedwordpress`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2024-0839, CVE-2021-25055 and CVE-2015-4018, so operators can jump from disclosure to patch validation without scanning the full feed first.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
FeedWordPress < 2015.0514 - SQL Injection
FeedWordPress <= 2021.0713 - Reflected Cross-Site Scripting
FeedWordPress < 2015.0514 - Reflected Cross-Site Scripting
FeedWordPress <= 2022.0222 - Insecure Direct Object Referece
This hub clusters every indexed record for FeedWordPress so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missing validation on the user controlled 'gui...
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authenticated users to execute arbitrary SQL co...
Sorted by latest disclosure date so newly published issues surface first.
The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missing validation on the user controlled 'guid' key. This makes it possible for unauthenticated attackers to view draft posts that may...
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the link_ids[] parameter in an Update action in the syndication.php page to wp-...
The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg().
The FeedWordPress plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 2015.0426 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a vict...