RESTful Content Syndication
RESTful Content Syndication has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Unrestricted Upload Of File With Dangerous Type, behind 1 of the records (100%).
The one issue recorded for RESTful Content Syndication has a vendor fix available, so running the current release closes it.
All of these findings were reported by kr0d. RESTful Content Syndication is installed on roughly 70 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.0.
CVE-2025-12171RESTful Content Syndication 1.1.0 - 1.5.0 - Authenticated (Contributor+) Arbitrary File Upload
Read the full analysisVulnerability Records

RESTful Content Syndication
Author
Anthony Eden
RESTful Syndication allows you to automatically ingest content from other WordPress sites, using the WordPress REST API. This can allow you to run a network of sites, which all receive the same post content. There is a small selection of options, allowing you select the author, default post status, automatically create the appropriate terms, and set the Yoast No-Index status.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C