CVE-2025-7828: Evigeo Wp Filter & Combine Rss Feeds

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The WP Filter & Combine RSS Feeds plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the post_listing_page() function in all versions up to, and including, 0.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete feeds.

Affected products

  • Evigeo Wp Filter & Combine Rss Feeds: up to and including 0.4

Published 2025-08-23. Last modified 2026-06-17.