FeedWordPress
FeedWordPress has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2024; all 5 are fixed as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high. 2015 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (60%). Other recurring categories include Authorization Bypass Through User-Controlled Key, SQL Injection.
Every one of the 5 issues recorded for FeedWordPress has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, most of them (2) reported by quassy. FeedWordPress is installed on roughly 9,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2015-4018FeedWordPress < 2015.0514 - SQL Injection
Read the full analysisVulnerability Records

FeedWordPress
Author
C. Johnson
Author: C. Johnson Project URI: http://fwpplugin.com/ License: GPL 2. See License below for copyright jots and tittles. FeedWordPress is an Atom/RSS aggregator for WordPress. It syndicates content from feeds that you choose into your WordPress weblog, and then the content it syndicates appears as a series of special posts in your WordPress posts database. If you syndicate several feeds then you can use WordPress’s posts database and templating engine as the back-end of an aggregation (“planet”) website. It was developed, originally, as a utility/hobby project, because I needed a more flexible replacement for Planet for aggregator sites that I administered. FeedWordPress is designed with flexibility, ease of use, and ease of configuration in mind. You’ll need a working installation of WordPress (version 4.5 or later), and it helps to have SFTP or FTP access to your web host. The ability to create cron jobs on your web host is helpful but not required. Using and Customizing FeedWordPress FeedWordPress has many options which can be accessed through the WordPress Dashboard, and a lot of functionality accessible programmatically through WordPress templates or plugins. For further documentation of the ins and outs, see the documentation at the FeedWordPress project homepage. License The FeedWordPress plugin is copyright © 2005-2021 by Charles Johnson. It uses code derived or translated from: wp-rss-aggregate.php by Kellan Elliot-McCrea SimplePie feed parser by Ryan Parman, Geoffrey Sneddon, Ryan McCue, et al. MagpieRSS feed parser by Kellan Elliot-McCrea Ultra-Liberal Feed Finder by Mark Pilgrim WordPress Blog Tool and Publishing Platform according to the terms of the GNU General Public License. This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C