CVE-2024-1317
WordPress vulnerability analysis and mitigation

Overview

A critical SQL injection vulnerability was discovered in the RSS Aggregator by Feedzy WordPress plugin, identified as CVE-2024-1317 with a CVSS score of 8.8. The vulnerability affects all versions up to and including 4.4.2 of the plugin, which has over 50,000 active installations. The flaw was discovered on February 1, 2024, and was patched with the release of version 4.4.3 on February 9, 2024 (Security Online).

Technical details

The vulnerability stems from insufficient escaping of user-supplied parameters in the 'search_key' parameter within the fetch_custom_fields() function of the Feedzy_Rss_Feeds_Import class. The issue was exacerbated by the removal of WordPress's global default magic quotes protection through the filter_input() function with FILTER_UNSAFE_RAW. The vulnerability manifests due to improper implementation of the wpdb prepare() function, where the $like value was directly appended to the query instead of being properly parameterized (Security Online).

Impact

The vulnerability allows authenticated attackers with contributor-level permissions or higher to perform SQL injection attacks, potentially exposing sensitive information from the database, including password hashes. The plugin's widespread use in content-rich sites for features such as feed to post conversions and RSS feed displays makes this vulnerability particularly concerning (Security Online).

Exploitability

The vulnerability can be exploited through both time-based blind SQL injection and UNION-based SQL injection methods. The UNION-based approach allows for faster data extraction, making it particularly dangerous. The attack requires authentication with at least contributor-level access to the WordPress installation (Security Online).

Mitigation and workarounds

Website administrators using the Feedzy RSS Aggregator plugin should immediately update to version 4.4.3 or later, which contains the security patch. The vulnerability was reported through the Wordfence Bug Bounty Program and was promptly addressed by Themeisle, the plugin's developers (Security Online).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78361CRITICAL9.1
  • zipmoney-payments-woocommerce
NoYesSep 10, 2026
CVE-2026-82925HIGH8.1
  • site-reviews
NoYesSep 10, 2026
CVE-2026-77771HIGH7.5
  • miniorange-2-factor-authentication
NoYesSep 10, 2026
CVE-2026-81431HIGH7.2
  • registration-form-for-woocommerce
NoYesSep 10, 2026
CVE-2026-15889MEDIUM6.4
  • aruba-hispeed-cache
NoYesSep 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management