
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical SQL injection vulnerability was discovered in the RSS Aggregator by Feedzy WordPress plugin, identified as CVE-2024-1317 with a CVSS score of 8.8. The vulnerability affects all versions up to and including 4.4.2 of the plugin, which has over 50,000 active installations. The flaw was discovered on February 1, 2024, and was patched with the release of version 4.4.3 on February 9, 2024 (Security Online).
The vulnerability stems from insufficient escaping of user-supplied parameters in the 'search_key' parameter within the fetch_custom_fields() function of the Feedzy_Rss_Feeds_Import class. The issue was exacerbated by the removal of WordPress's global default magic quotes protection through the filter_input() function with FILTER_UNSAFE_RAW. The vulnerability manifests due to improper implementation of the wpdb prepare() function, where the $like value was directly appended to the query instead of being properly parameterized (Security Online).
The vulnerability allows authenticated attackers with contributor-level permissions or higher to perform SQL injection attacks, potentially exposing sensitive information from the database, including password hashes. The plugin's widespread use in content-rich sites for features such as feed to post conversions and RSS feed displays makes this vulnerability particularly concerning (Security Online).
The vulnerability can be exploited through both time-based blind SQL injection and UNION-based SQL injection methods. The UNION-based approach allows for faster data extraction, making it particularly dangerous. The attack requires authentication with at least contributor-level access to the WordPress installation (Security Online).
Website administrators using the Feedzy RSS Aggregator plugin should immediately update to version 4.4.3 or later, which contains the security patch. The vulnerability was reported through the Wordfence Bug Bounty Program and was promptly addressed by Themeisle, the plugin's developers (Security Online).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."