RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Security & Risk Analysis

wordpress.org/plugins/feedzy-rss-feeds

The most powerful WordPress RSS aggregator, helping you curate content, autoblog, import RSS & display unlimited RSS feeds within a few minutes.

40K active installs v5.1.2 PHP 7.2+ WP 6.0+ Updated Dec 12, 2025
autobloggingfeed-to-postnews-aggregatorrss-aggregatorrss-import
92
A · Safe
CVEs total11
Unpatched0
Last CVEDec 10, 2025
Safety Verdict

Is RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Safe to Use in 2026?

Generally Safe

Score 92/100

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator has a strong security track record. Known vulnerabilities have been patched promptly.

11 known CVEsLast CVE: Dec 10, 2025Updated 3mo ago
Risk Assessment

The Feedzy RSS Feeds plugin version 5.1.2 exhibits a mixed security posture. While it demonstrates good practices like a high percentage of prepared SQL statements and properly escaped output, several areas raise concerns. The significant attack surface, with 6 out of 11 entry points lacking authorization checks, is a primary risk. This includes 6 unprotected AJAX handlers, which are often exploited for privilege escalation or unauthorized actions if not properly secured. Taint analysis, although showing no critical or high severity flows, did reveal 3 flows with unsanitized paths, indicating potential for local file inclusion or other path manipulation vulnerabilities. The plugin's vulnerability history is particularly worrying, with 11 known CVEs, all of which are listed as currently patched. However, the past prevalence of critical and high severity vulnerabilities like SSRF, XSS, SQL Injection, and Missing Authorization suggests a pattern of security weaknesses that have required significant patching over time. The fact that all past vulnerabilities are patched is positive, but the sheer number and types of past issues, coupled with the current unprotected attack surface, warrants caution.

Key Concerns

  • Large attack surface without auth checks
  • Unsanitized paths in taint analysis
  • High number of known CVEs in history
Vulnerabilities
11

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Security Vulnerabilities

CVEs by Year

1 CVE in 2020
2020
1 CVE in 2023
2023
7 CVEs in 2024
2024
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
10

11 total CVEs

CVE-2025-11467medium · 5.8Server-Side Request Forgery (SSRF)

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated Blind Server-Side Request Forgery

Dec 10, 2025 Patched in 5.1.2 (1d)
CVE-2025-11128medium · 5Server-Side Request Forgery (SSRF)

Feedzy RSS Feeds Lite <= 5.1.0 - Authenticated (Subscriber+) Server-Side Request Forgery

Oct 22, 2025 Patched in 5.1.1 (2d)
CVE-2023-6805medium · 6.4Server-Side Request Forgery (SSRF)

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF)

Apr 16, 2024 Patched in 4.4.8 (105d)
CVE-2023-6877medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error Message

Apr 6, 2024 Patched in 4.3.4 (115d)
CVE-2024-1318medium · 6.5Missing Authorization

RSS Aggregator by Feedzy <= 4.4.2 - Missing Authorization to Arbitrary Page Creation and Publication

Feb 9, 2024 Patched in 4.4.3 (12d)
CVE-2024-1317high · 8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

RSS Aggregator by Feedzy <= 4.4.2 - Authenticated(Contributor+) SQL Injection

Feb 9, 2024 Patched in 4.4.3 (12d)
CVE-2024-1092medium · 4.3Improper Access Control

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing Authorization

Feb 2, 2024 Patched in 4.4.2 (4d)
CVE-2023-6801medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Authenticated (Author+) Stored Cross-Site Scripting

Jan 5, 2024 Patched in 4.3.3 (207d)
CVE-2023-6798medium · 5.4Missing Authorization

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Missing Authorization

Jan 5, 2024 Patched in 4.3.3 (207d)
CVE-2022-4667medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

RSS Aggregator by Feedzy <= 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Jan 4, 2023 Patched in 4.1.1 (384d)
CVE-2020-36758medium · 4.3Cross-Site Request Forgery (CSRF)

RSS Aggregator by Feedzy <= 3.4.2 - Cross-Site Request Forgery Bypass

Sep 16, 2020 Patched in 3.4.3 (1224d)
Code Analysis
Analyzed Mar 16, 2026

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
7 prepared
Unescaped Output
27
746 escaped
Nonce Checks
26
Capability Checks
12
File Operations
6
External Requests
5
Bundled Libraries
0

SQL Query Safety

88% prepared8 total queries

Output Escaping

97% escaped773 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

9 flows3 with unsanitized paths
ajax (includes\admin\feedzy-rss-feeds-admin.php:1854)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Attack Surface

Entry Points11
Unprotected6

AJAX Handlers 7

authwp_ajax_dismiss_themeisle_sale_notice_feedzyincludes\feedzy-rss-feeds-limited-offers.php:95
authwp_ajax_get_tinymce_formincludes\feedzy-rss-feeds.php:181
authwp_ajax_feedzy_categoriesincludes\feedzy-rss-feeds.php:184
authwp_ajax_feedzy_validate_feedincludes\feedzy-rss-feeds.php:206
authwp_ajax_feedzy_dashboard_subscribeincludes\feedzy-rss-feeds.php:207
authwp_ajax_feedzy_wizard_step_processincludes\feedzy-rss-feeds.php:228
authwp_ajax_feedzyincludes\feedzy-rss-feeds.php:241

REST API Routes 3

GET/wp-json/feedzy/v1/logs/downloadincludes\admin\feedzy-rss-feeds-log.php:693
DELETE/wp-json/feedzy/v1/logsincludes\admin\feedzy-rss-feeds-log.php:704
POST/wp-json/feedzy/v1/feed/includes\gutenberg\feedzy-rss-feeds-gutenberg-block.php:281

Shortcodes 1

[feedzy-rss] includes\feedzy-rss-feeds.php:215
WordPress Hooks 146
filterthemeisle_sdk_productsfeedzy-rss-feed.php:147
filterpirate_parrot_logfeedzy-rss-feed.php:148
filterfeedzy_rss_feeds_about_us_metadatafeedzy-rss-feed.php:160
filterfeedzy_rss_feeds_welcome_metadatafeedzy-rss-feed.php:172
filterfeedzy_rss_feeds_welcome_upsell_messagefeedzy-rss-feed.php:195
filterfeedzy_rss_feeds_feedback_review_button_dofeedzy-rss-feed.php:215
filterfeedzy_rss_feeds_feedback_review_button_cancelfeedzy-rss-feed.php:221
actionthemeisle_log_eventfeedzy-rss-feed.php:264
filterfeedzy_rss_feeds_float_widget_metadatafeedzy-rss-feed.php:284
filterthemeisle_sdk_labelsfeedzy-rss-feed.php:300
filterwp_feed_cache_transient_lifetimeincludes\abstract\feedzy-rss-feeds-admin-abstract.php:868
filterwp_targeted_link_relincludes\admin\feedzy-rss-feeds-actions.php:603
filterthemeisle_sdk_blackfriday_dataincludes\admin\feedzy-rss-feeds-admin.php:79
actionthemeisle_internal_pageincludes\admin\feedzy-rss-feeds-admin.php:84
actionadmin_headincludes\admin\feedzy-rss-feeds-admin.php:433
actionadminmenuincludes\admin\feedzy-rss-feeds-admin.php:1312
actionadmin_footerincludes\admin\feedzy-rss-feeds-admin.php:1333
filterhttp_headers_useragentincludes\admin\feedzy-rss-feeds-admin.php:1522
filterhttp_request_argsincludes\admin\feedzy-rss-feeds-admin.php:1525
filterpre_http_send_through_proxyincludes\admin\feedzy-rss-feeds-admin.php:1575
actionadmin_enqueue_scriptsincludes\admin\feedzy-rss-feeds-admin.php:1970
actionadmin_noticesincludes\admin\feedzy-rss-feeds-admin.php:2746
filterthemeisle_sdk_enable_telemetryincludes\admin\feedzy-rss-feeds-admin.php:3004
filterwp_kses_allowed_htmlincludes\admin\feedzy-rss-feeds-import.php:728
actionsave_post_feedzy_importsincludes\admin\feedzy-rss-feeds-import.php:756
actionsave_post_feedzy_importsincludes\admin\feedzy-rss-feeds-import.php:1321
filterfeedzy_default_errorincludes\admin\feedzy-rss-feeds-import.php:1417
filterwp_targeted_link_relincludes\admin\feedzy-rss-feeds-import.php:2019
filterwpseo_canonicalincludes\admin\feedzy-rss-feeds-import.php:3548
filteraioseop_canonical_urlincludes\admin\feedzy-rss-feeds-import.php:3551
filterget_canonical_urlincludes\admin\feedzy-rss-feeds-import.php:3555
actionadmin_footerincludes\admin\feedzy-rss-feeds-import.php:4165
actiontask_feedzy_send_error_reportincludes\admin\feedzy-rss-feeds-task-manager.php:22
actionupdate_option_feedzy-settingsincludes\admin\feedzy-rss-feeds-task-manager.php:27
actiontask_feedzy_cleanup_logsincludes\admin\feedzy-rss-feeds-task-manager.php:34
actioninitincludes\admin\feedzy-rss-feeds-task-manager.php:39
filtermce_external_pluginsincludes\admin\feedzy-rss-feeds-ui.php:86
filtermce_buttonsincludes\admin\feedzy-rss-feeds-ui.php:87
filtermce_external_languagesincludes\admin\feedzy-rss-feeds-ui.php:88
actionadmin_enqueue_scriptsincludes\admin\feedzy-rss-feeds-ui.php:89
filtertiny_mce_before_initincludes\admin\feedzy-rss-feeds-ui.php:90
actionin_admin_headerincludes\admin\feedzy-rss-feeds-ui.php:91
filterscreen_options_show_screenincludes\admin\feedzy-rss-feeds-ui.php:207
actionadmin_noticesincludes\admin\feedzy-rss-feeds-ui.php:210
actionelementor/editor/after_enqueue_stylesincludes\elementor\feedzy-rss-feeds-elementor.php:45
filterthe_excerpt_rssincludes\feedzy-rss-feeds-feed-tweaks.php:34
filterthe_content_feedincludes\feedzy-rss-feeds-feed-tweaks.php:35
filterpost_thumbnail_htmlincludes\feedzy-rss-feeds-feed-tweaks.php:93
filterelementor/image_size/get_attachment_image_htmlincludes\feedzy-rss-feeds-feed-tweaks.php:153
filterhas_post_thumbnailincludes\feedzy-rss-feeds-feed-tweaks.php:194
filterwp_get_attachment_image_srcincludes\feedzy-rss-feeds-feed-tweaks.php:215
filterfeedzy_wp_kses_allowed_htmlincludes\feedzy-rss-feeds-feed-tweaks.php:426
filterthemeisle_products_deal_priorityincludes\feedzy-rss-feeds-limited-offers.php:93
actionadmin_noticesincludes\feedzy-rss-feeds-limited-offers.php:94
actionadmin_noticesincludes\feedzy-rss-feeds-limited-offers.php:412
actionadmin_initincludes\feedzy-rss-feeds.php:168
actionwp_headincludes\feedzy-rss-feeds.php:170
actionadmin_initincludes\feedzy-rss-feeds.php:171
actioninitincludes\feedzy-rss-feeds.php:172
actionadmin_footerincludes\feedzy-rss-feeds.php:173
actionsave_postincludes\feedzy-rss-feeds.php:174
actionfeedzy_pre_http_setupincludes\feedzy-rss-feeds.php:175
actionfeedzy_post_http_teardownincludes\feedzy-rss-feeds.php:176
actionadmin_initincludes\feedzy-rss-feeds.php:177
actionmanage_feedzy_categories_posts_custom_columnincludes\feedzy-rss-feeds.php:178
actionadmin_menuincludes\feedzy-rss-feeds.php:179
actionadmin_menuincludes\feedzy-rss-feeds.php:180
actionwp_enqueue_scriptsincludes\feedzy-rss-feeds.php:182
actionadmin_enqueue_scriptsincludes\feedzy-rss-feeds.php:183
actionadmin_action_feedzy_dismiss_wizardincludes\feedzy-rss-feeds.php:185
filtermanage_feedzy_categories_posts_columnsincludes\feedzy-rss-feeds.php:187
filterplugin_row_metaincludes\feedzy-rss-feeds.php:188
filterfeedzy_default_imageincludes\feedzy-rss-feeds.php:189
filterfeedzy_default_errorincludes\feedzy-rss-feeds.php:190
filterfeedzy_item_attributesincludes\feedzy-rss-feeds.php:191
filterfeedzy_item_attributesincludes\feedzy-rss-feeds.php:192
filterfeedzy_register_optionsincludes\feedzy-rss-feeds.php:193
filterfeedzy_summary_inputincludes\feedzy-rss-feeds.php:194
filterfeedzy_get_feed_arrayincludes\feedzy-rss-feeds.php:195
filterfeedzy_process_feed_sourceincludes\feedzy-rss-feeds.php:196
filterfeedzy_get_feed_urlincludes\feedzy-rss-feeds.php:197
filterfeedzy_get_settingsincludes\feedzy-rss-feeds.php:198
filterfeedzy_rss_feeds_logger_dataincludes\feedzy-rss-feeds.php:199
filterfeedzy_check_source_validityincludes\feedzy-rss-feeds.php:200
filterfeedzy_get_source_validity_errorincludes\feedzy-rss-feeds.php:201
filterpost_row_actionsincludes\feedzy-rss-feeds.php:202
filteradmin_footerincludes\feedzy-rss-feeds.php:203
actioncurrent_screenincludes\feedzy-rss-feeds.php:204
actioninitincludes\feedzy-rss-feeds.php:205
filterfeedzy_internal_cron_schedule_slugsincludes\feedzy-rss-feeds.php:208
filtercron_schedulesincludes\feedzy-rss-feeds.php:209
filterupdate_post_metadataincludes\feedzy-rss-feeds.php:212
filteradd_post_metadataincludes\feedzy-rss-feeds.php:213
actionwidgets_initincludes\feedzy-rss-feeds.php:217
actionrest_api_initincludes\feedzy-rss-feeds.php:224
actionadmin_body_classincludes\feedzy-rss-feeds.php:227
actionfeedzy_upsell_classincludes\feedzy-rss-feeds.php:234
actionfeedzy_upsell_contentincludes\feedzy-rss-feeds.php:235
actionadmin_enqueue_scriptsincludes\feedzy-rss-feeds.php:236
actioninitincludes\feedzy-rss-feeds.php:237
actionadd_meta_boxesincludes\feedzy-rss-feeds.php:238
actionfeedzy_cronincludes\feedzy-rss-feeds.php:239
actionsave_post_feedzy_importsincludes\feedzy-rss-feeds.php:240
actionmanage_feedzy_imports_posts_custom_columnincludes\feedzy-rss-feeds.php:242
actionwpincludes\feedzy-rss-feeds.php:243
filterpre_get_postsincludes\feedzy-rss-feeds.php:244
filterfeedzy_items_limitincludes\feedzy-rss-feeds.php:246
filterfeedzy_settings_tabsincludes\feedzy-rss-feeds.php:247
filterfeedzy_integration_tabsincludes\feedzy-rss-feeds.php:248
filterredirect_post_locationincludes\feedzy-rss-feeds.php:249
filtermanage_feedzy_imports_posts_columnsincludes\feedzy-rss-feeds.php:250
actionadmin_noticesincludes\feedzy-rss-feeds.php:251
actioninitincludes\feedzy-rss-feeds.php:252
filterfeedzy_item_filterincludes\feedzy-rss-feeds.php:253
filterfeedzy_display_tab_settingsincludes\feedzy-rss-feeds.php:254
filterfeedzy_save_tab_settingsincludes\feedzy-rss-feeds.php:255
filterfeedzy_render_magic_tagsincludes\feedzy-rss-feeds.php:256
filterfeedzy_magic_tags_titleincludes\feedzy-rss-feeds.php:257
filterfeedzy_magic_tags_dateincludes\feedzy-rss-feeds.php:258
filterfeedzy_magic_tags_contentincludes\feedzy-rss-feeds.php:259
filterfeedzy_magic_tags_imageincludes\feedzy-rss-feeds.php:260
filterfeedzy_retrieve_categoriesincludes\feedzy-rss-feeds.php:261
filterfeedzy_is_license_of_typeincludes\feedzy-rss-feeds.php:262
filterpost_row_actionsincludes\feedzy-rss-feeds.php:263
filterwp_kses_allowed_htmlincludes\feedzy-rss-feeds.php:264
filterfeedzy_magic_tags_post_excerptincludes\feedzy-rss-feeds.php:265
actionadmin_action_feedzy_clone_import_jobincludes\feedzy-rss-feeds.php:266
actionadmin_noticesincludes\feedzy-rss-feeds.php:267
actionload-edit.phpincludes\feedzy-rss-feeds.php:268
actionelementor/experiments/feature-registeredincludes\feedzy-rss-feeds.php:270
filterelementor/widgets/black_listincludes\feedzy-rss-feeds.php:272
actionelementor/widgets/registerincludes\feedzy-rss-feeds.php:275
actionelementor/controls/registerincludes\feedzy-rss-feeds.php:276
actionelementor/frontend/before_enqueue_stylesincludes\feedzy-rss-feeds.php:277
actionfeedzy_filter_conditions_migrationincludes\feedzy-rss-feeds.php:280
actionfeedzy_filter_conditions_attributeincludes\feedzy-rss-feeds.php:281
actionfeedzy_item_keywordincludes\feedzy-rss-feeds.php:282
actionfeedzy_logincludes\feedzy-rss-feeds.php:288
filterfeedzy_disable_db_cacheincludes\feedzy-rss-feeds.php:304
actionplugins_loadedincludes\feedzy-rss-feeds.php:314
actionenqueue_block_editor_assetsincludes\gutenberg\feedzy-rss-feeds-gutenberg-block.php:44
actionrest_api_initincludes\gutenberg\feedzy-rss-feeds-gutenberg-block.php:45
actioninitincludes\gutenberg\feedzy-rss-feeds-gutenberg-block.php:46
filterthemeisle_sdk_enable_telemetryincludes\gutenberg\feedzy-rss-feeds-gutenberg-block.php:88
actioninitincludes\gutenberg\feedzy-rss-feeds-loop-block.php:51
filterfeedzy_loop_itemincludes\gutenberg\feedzy-rss-feeds-loop-block.php:52
Maintenance & Trust

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 12, 2025
PHP min version7.2
Downloads2.9M

Community Trust

Rating92/100
Number of ratings359
Active installs40K
Developer Profile

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Developer Profile

Themeisle

37 plugins · 2.2M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
420 days
View full developer profile
Detection Fingerprints

How We Detect RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/feedzy-rss-feeds/css/feedzy-rss-feeds.css/wp-content/plugins/feedzy-rss-feeds/css/feedzy-rss-feeds-public.css/wp-content/plugins/feedzy-rss-feeds/css/feedzy-rss-feeds-elementor.css/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds.js/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds-public.js/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds-gutenberg.js/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds-elementor.js
Script Paths
/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds.js/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds-public.js/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds-gutenberg.js/wp-content/plugins/feedzy-rss-feeds/js/feedzy-rss-feeds-elementor.js
Version Parameters
feedzy-rss-feeds/css/feedzy-rss-feeds.css?ver=feedzy-rss-feeds/css/feedzy-rss-feeds-public.css?ver=feedzy-rss-feeds/css/feedzy-rss-feeds-elementor.css?ver=feedzy-rss-feeds/js/feedzy-rss-feeds.js?ver=feedzy-rss-feeds/js/feedzy-rss-feeds-public.js?ver=feedzy-rss-feeds/js/feedzy-rss-feeds-gutenberg.js?ver=feedzy-rss-feeds/js/feedzy-rss-feeds-elementor.js?ver=

HTML / DOM Fingerprints

CSS Classes
feedzy-rss-feed
Data Attributes
data-feedzy-id
JS Globals
feedzy_rss_feeds_paramsfeedzy_rss_feeds_public_params
REST Endpoints
/wp-json/feedzy/v1/feed/
FAQ

Frequently Asked Questions about RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator