CVE-2026-86707 PUBLISHED

Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' Parameter

Assigner: WPScan
Reserved: 08.09.2026 Published: 17.09.2026 Updated: 17.09.2026

The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.

Product Status

Vendor Unknown
Product Private Feed Key
Versions Default: unknown
  • affected from 0 to 0.1 (incl.)

Credits

  • Naoki Kawahigashi finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE