CVE-2026-86707
The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
- Published Sep 17, 2026
- CVSS 9.8 critical
- 0.5% chance of exploitation in the next 30 days (EPSS)