An invalid XML error in a WordPress RSS feed means the reader could not parse the response it received. The cause may be malformed feed content, unexpected PHP output, a login page or a security challenge. Fetch the exact feed URL before changing WordPress settings.
Preserve the reader's error, URL, time and line number if provided. A visually normal homepage does not prove the feed works. Readers can also retain an older response, so compare their report with a fresh request to the same endpoint.
Confirm which feed is failing
WordPress has post feeds, comment feeds and other scoped feeds. The feed handbook explains their different purposes. Test the URL the subscriber actually uses, including any category path or query string.
For your own public feed, inspect a saved response rather than sending a private or tokenized URL to an unknown online validator:
curl -sS --max-time 20 -D feed-headers.txt 'https://example.com/feed/' -o feed-response.xml
Replace the example domain. These files may contain unpublished or sensitive material if the endpoint is misconfigured, so keep them private. Inspect the status and redirect destination before judging the body as RSS.
Classify the first unexpected bytes
A response beginning with a login page or browser challenge is not an XML formatting problem. A PHP warning ahead of the feed document suggests unintended output. An XML parser pointing inside one item's content may indicate bad escaping or a plugin's custom element.
Endpoint: Post feed, comment feed or scoped feed?. Response: Status, destination, content type and first bytes. Repair: Correct the emitting or delivery component. Reader: Newest public item parses without private leaks. Original explanatory guide, not a customer test result.
Keep the distinction precise. A 200 status can still carry HTML, and an XML content type cannot repair an invalid body. Compare a working feed and the failing one on the same site to narrow the scope without making broad server changes.
Repair the component that emits the response
On a private staging copy, reproduce the failure and isolate the last relevant plugin or theme change. If warnings contaminate output, fix their cause and configure private logging with display disabled. The WordPress debugging guide explains the separation. Do not simply suppress evidence and declare the underlying error fixed.
For a security challenge, ask the firewall administrator to review the specific public read-only feed route. Preserve authentication for private feeds and avoid disabling the firewall globally. For a malformed custom field, have the responsible extension encode content correctly rather than deleting arbitrary characters across the database.
The invalid JSON response guide covers a related response-classification method for editor saves. Do not apply write-endpoint exceptions to RSS just because both failures involve parsing.
Verify the subscriber path
After the origin produces valid feed data, refresh only relevant cache entries and retry the actual reader. Confirm the newest expected public entry, its canonical link and publication time. Check that drafts and protected content remain excluded.
Request feed repair with the sanitized first failing bytes, parser message and affected route. Record whether the fix addressed output generation, delivery or reader caching. A successful browser view without a successful reader refresh is an incomplete test.
Sources checked October 1, 2026. Instructions and visuals are explanatory, not claims of customer tests.