← Back to CVE List
CVE-2026-86707Wordfence
Vulnerability Summary
The Private Feed Key plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators.
CVSS v3.1 Base Metrics — Score 9.8 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Private Feed Key * - 0.1
Not provided by Wordfence for this CVE.