CRITICAL
9.8 CVE-2026-86707 Published 17 Sept 2026
WordPress Private Feed Key Plugin Auth Bypass
Worried this affects your website?
The Private Feed Key WordPress plugin, version 0.1 and earlier, contains a critical authentication bypass vulnerability. It fails to verify the key used to authenticate a feed request, allowing attackers to log in as any user, including administrators, without any authentication.
Impact: Unauthenticated attackers can gain full user privileges, including administrative access.
Reference: CVE-2026-86707 on NVD
← Back to Security News