The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
https://wpscan.com/vulnerability/fbf22345-4e8c-4719-a9c3-5e606b6fd77f/