CVE-2026-86707: Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' Parameter
Published Sep 17, 2026
·Updated
The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
Affected Software
1 affected component
WordPress Private Feed Key<0.1
Event History
Sep 17, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker only needs to make a feed request with a crafted feedkey parameter. No prior authentication is required.
2
Which accounts can be compromised?
Any WordPress user account can be impersonated, including administrator accounts.
3
Which plugin versions are affected?
The issue affects Private Feed Key versions through 0.1.