CVE-2024-1092: RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing Authorization
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers, with contributor access or higher, to create, edit or delete feed categories created by them.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregatorto a version that resolves this vulnerability.Fixed in 4.4.1 - Compensating control
Restrict access to the feedzy dashboard (Feedzy RSS Aggregator admin/dashboard) so only trusted administrators can manage feed categories; do not allow contributor-level accounts to access the dashboard.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1092?
CVE-2024-1092 has a severity rating that indicates a high risk of unauthorized data modification.
How do I fix CVE-2024-1092?
To fix CVE-2024-1092, update the RSS Aggregator by Feedzy plugin to version 4.4.2 or later.
Who is affected by CVE-2024-1092?
CVE-2024-1092 affects all versions of the RSS Aggregator by Feedzy plugin up to and including 4.4.1 installed on WordPress.
What type of vulnerability is CVE-2024-1092?
CVE-2024-1092 is a vulnerability that allows unauthorized data modification due to a missing capability check.
Is there a workaround for CVE-2024-1092?
Currently, there is no official workaround for CVE-2024-1092, so updating the plugin is the recommended solution.