CodeRevolution Vulnerabilities and Affected Products
Vulnerabilities associated with Echo RSS Feed Post Generator.
Products
Clear product- Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit4 vulnerabilities
- Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit2 vulnerabilities
- Crawlomatic Multipage Scraper Post Generator2 vulnerabilities
- Crawlomatic Multisite Scraper Post Generator2 vulnerabilities
- Echo RSS Feed Post Generator2 vulnerabilities
- WP Pocket URLs2 vulnerabilities
- Aimogen Pro1 vulnerability
- Aiomatic1 vulnerability
- aiomatic-automatic_ai_content_writer_\&_editor1 vulnerability
- Demo My WordPress1 vulnerability
- demo_my_wordpress1 vulnerability
- Echo RSS Feed Post Generator Plugin for WordPress1 vulnerability
- echo_rss_feed_post_generator1 vulnerability
- WP Setup Wizard1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-4391CRITICAL | Echo RSS Feed Post Generator <= 5.4.8.1 - Unauthenticated Arbitrary File UploadThe Echo RSS Feed Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the echo_generate_featured_image() function in all versions up to, and including, 5.4.8.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. CWE-434May 17, 2025 | CVSS9.8v3.1 | EPSS0.687% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9265CRITICAL | Echo RSS Feed Post Generator <= 5.4.6 - Unauthenticated Privilege EscalationThe Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due to the plugin not properly restricting the roles that can set during registration through the echo_check_post_header_sent() function. This makes it possible for unauthenticated attackers to register as an administrator. CWE-269Oct 1, 2024 | CVSS9.8v3.1 | EPSS0.613% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |