CVE-2023-6798: RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Missing Authorization
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check when updating settings in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with author-level access or above to change the plugin's settings including proxy settings, which are also exposed to authors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6798?
CVE-2023-6798 has been classified as a high-severity vulnerability due to the potential for unauthorized settings updates.
How do I fix CVE-2023-6798?
To fix CVE-2023-6798, update the RSS Aggregator by Feedzy plugin to version 4.3.3 or later.
Who is affected by CVE-2023-6798?
All users of the RSS Aggregator by Feedzy plugin for WordPress versions up to and including 4.3.2 are affected by CVE-2023-6798.
What kind of attack is possible with CVE-2023-6798?
CVE-2023-6798 allows attackers to update settings without authorization due to a missing capability check.
Is CVE-2023-6798 being actively exploited?
There have been reports indicating that CVE-2023-6798 could potentially be exploited in the wild.