Sceawere

Vulnerability Detail

CVE-2026-104735UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Feedzy Stored Cross-Site Scripting

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
3h ago
Vendor
themeisle
Product
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Feedzy Loop Block Feed URL / RSS <title> in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is not neutralized at save time because post_content stores only a benign block reference to an external feed URL; the malicious HTML is injected at render time from the attacker-controlled RSS feed title, bypassing any save-time wp_kses filtering.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-10T05:16:39.753Z",
  "pubdate": "2026-10-10T05:16:39.753Z",
  "executiveSummary": "The Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 5.2.10.\nThis vulnerability originates from improper input sanitization and output escaping within the plugin's Feedzy Loop block rendering mechanism.\nAn authenticated attacker with at least contributor-level privileges can inject malicious JavaScript payloads into an external RSS feed source. Because the plugin fetches and renders the RSS title content dynamically, the malicious script is executed in the browser of any user viewing a page containing the injected Feedzy Loop block.\nThe risk is significant as it allows for unauthorized actions, session hijacking, or redirection of administrative users by authenticated contributors. The vulnerability bypasses standard security filters during the initial save process because the malicious payload is only introduced during the rendering phase.",
  "technicalDetails": "The vulnerability resides in the dynamic rendering logic of the Feedzy Loop block, specifically how the plugin handles the 'title' attribute retrieved from external RSS feeds. The root cause is a failure to apply sufficient output sanitization when rendering the RSS feed data on the WordPress front-end.\nIn the plugin's architecture, the post_content field stores a block reference pointing to an external feed URL. Crucially, the plugin does not execute wp_kses or other equivalent neutralization filters on the retrieved RSS content during the storage process. Instead, the raw content—including potential script tags—is stored by the plugin as part of the feed metadata.\nThe exploitation flow begins when an attacker, possessing contributor-level access, inserts a Feedzy Loop block into a post. The attacker configures this block to point to a malicious, attacker-controlled RSS feed. Within this external RSS feed, the attacker crafts a malicious payload inside the <title> tag (e.g., <script>alert('XSS')</script>).\nWhen the WordPress post is saved, the internal storage mechanism does not trigger a security warning because it perceives the feed configuration as a standard URL reference. However, when a victim accesses the post on the site, the plugin invokes its rendering engine to fetch and display the feed data. During this render-time execution, the plugin pulls the attacker-supplied malicious title from the remote RSS source and injects it directly into the Document Object Model (DOM) of the page without prior sanitization.\nSince the script is injected directly into the rendered HTML, the browser treats it as legitimate source code and executes the payload within the context of the site's origin. This leads to Stored XSS, enabling the attacker to perform actions on behalf of the victim, potentially leading to privilege escalation or unauthorized data access if an administrator views the page. The lack of output encoding ensures that any payload hosted on the external server will successfully trigger execution upon every page load, making the attack persistent and highly effective for session-based attacks."
}
CVE-2026-104735: Feedzy Stored Cross-Site Scripting (MEDIUM Severity, CVSS: 6.4) | Sceawere