Feed Changer & Remover
Feed Changer & Remover has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Feed Changer & Remover has a vendor fix available, so running the current release closes it.
All of these findings were reported by Rio Darmawan. Feed Changer & Remover is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.
CVE-2023-25795Feed Changer <= 0.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Feed Changer & Remover
Author
Omid Shamloo
Do you want to disable your site’s feed? Don’t want to disable the address of the feed, but only want to access it yourself? This plugin is for you! Disable your site’s feed with just one tick. Or put a password on your feed so that only you can use it. Features Change main feed/rss/atom URL Disable main feed/rss/atom get new url many as many you want! This plugin is licensed under the Apache License, Version 2.0.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C