CVE-2026-104735: RSS Aggregator by Feedzy <= 5.2.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Feedzy Loop Block Feed URL / RSS <title>
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Feedzy Loop Block Feed URL / RSS <title> in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is not neutralized at save time because postcontent stores only a benign block reference to an external feed URL; the malicious HTML is injected at render time from the attacker-controlled RSS feed title, bypassing any save-time wpkses filtering.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and who is at risk of script execution?
An authenticated WordPress user with Contributor-level access or higher can exploit it. The injected script executes when another user accesses a page containing the attacker-controlled Feedzy Loop Block feed.
What does an attacker need to control?
The attacker needs Contributor-or-higher access and an RSS feed whose title they control. They use the Feedzy Loop Block feed URL while placing malicious HTML in the RSS <title> field, which is inserted when the page is rendered.
Why might normal content filtering not stop the payload?
The saved post content contains only a benign reference to the external feed URL. The malicious HTML arrives from the RSS title at render time, bypassing save-time wp_kses filtering.