VYPR

Private Feed Key

by WordPress

CVEs (1)

  • CVE-2026-86707Sep 17, 2026
    risk 0.00cvss epss

    The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.