CyberRota Analysis
AI-GeneratedThe Private Feed Key WordPress plugin versions up to 0.1 are vulnerable due to a lack of proper authentication verification for feed request keys, allowing unauthenticated attackers to impersonate any user, including those with administrative privileges. This vulnerability poses a significant risk of unauthorized access and potential exploitation of sensitive data within WordPress sites. WordPress site administrators and security teams should prioritize addressing this issue to mitigate the risk of account takeover and data breaches.
Original NVD Description
The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.