CRITICAL 9.8 CVE-2026-86707 Published 17 Sept 2026

WordPress Private Feed Key Plugin Auth Bypass

Worried this affects your website?

The Private Feed Key WordPress plugin, version 0.1 and earlier, contains a critical authentication bypass vulnerability. It fails to verify the key used to authenticate a feed request, allowing attackers to log in as any user, including administrators, without any authentication.

Impact: Unauthenticated attackers can gain full user privileges, including administrative access.

Reference: CVE-2026-86707 on NVD

← Back to Security News