FeedWordPress is a WordPress plugin that aggregates and republishes syndicated content, presenting a focused but widely embedded attack surface through its feed-parsing and content-management functions. The recurring vulnerabilities cluster around application-layer input handling—cross-site scripting, SQL injection, and authorization bypass—reflecting the challenges of safely processing untrusted syndicated data and managing editorial permissions within a plugin architecture. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Feedwordpress Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25055MEDIUM The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter. | Feb 21, 2022 | 6.1 | 31 | NO | YES |
CVE-2015-4018MEDIUM SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authenticated users to execute arbitr | May 21, 2015 | 6.5 | 27 | NO | YES |
CVE-2015-9358MEDIUM The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg(). | Aug 28, 2019 | 6.1 | 17 | NO | NO |
CVE-2024-0839MEDIUM The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missing validation on the user contr | Mar 13, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Feedwordpress Project.
Media articles that mention a CVE ID that affects a product developed by Feedwordpress Project — matched by CVE ID, not by vendor name.