{"id":18724296,"date":"2025-11-18T23:09:05","date_gmt":"2025-11-18T23:09:05","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/execrise-caution\/"},"modified":"2025-11-18T23:09:05","modified_gmt":"2025-11-18T23:09:05","slug":"execrise-caution","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/execrise-caution\/","title":{"rendered":"Execrise caution!"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">I was using version 4.2.8 which was called Feedzy RSS Feeds Lite. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Version 4.2.8 has dynamically loaded content, which may be vulnerable to remote code execution on a local wordpress instance. I noticed a couple of values in wp_options are changed to malicous ones, and this feedzy plugin is loading strange, advertisement values into memory\/database.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the Feedzy\u00a0plugin is benign, it at least has bugs susceptible for injections. <\/p>\n","protected":false},"template":"","class_list":["post-18724296","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18724296","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/18724296\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=18724296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}