Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-11128

Опубликовано: 23 окт. 2025
Источник: nvd
CVSS3: 5
EPSS Низкий

Описание

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query information from internal services.

EPSS

Процентиль: 15%
0.00047
Низкий

5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5
github
4 месяца назад

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query information from internal services.

EPSS

Процентиль: 15%
0.00047
Низкий

5 Medium

CVSS3

Дефекты

CWE-918