plugin

Rss Feed Widget Vulnerabilities

13 known security issues reported for the Rss Feed Widget WordPress plugin. Most recent disclosed Jan 7, 2026.

6 medium

Running Rss Feed Widget on your site? Check whether your installed version is affected.

Scan your site free

RSS Feed Widget <= 3.0.2 - Missing Authorization

medium

The RSS Feed Widget plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.0.2
Fixed in:
3.0.3
Disclosed:
Jan 7, 2026

CVE-2025-69349 on NVD →

RSS Feed Widget [rss-feed-widget] <= 3.0.2 (unfixed)

unknown

[en] Missing Authorization vulnerability in Fahad Mahmood RSS Feed Widget rss-feed-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RSS Feed Widget: from n/a through <= 3.0.2.

Affected:
up to 3.0.2
Fix:
No patched version reported
Disclosed:
Jan 6, 2026

CVE-2025-69349 on NVD →

RSS Feed Widget [rss-feed-widget] < 3.0.1

unknown

[en] The RSS Feed Widget WordPress plugin before 3.0.1 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Nov 12, 2024

CVE-2024-9835 on NVD →

RSS Feed Widget [rss-feed-widget] < 3.0.0

unknown

[en] The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Nov 12, 2024

CVE-2024-9836 on NVD →

RSS Feed Widget <= 2.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The RSS Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rfw-youtube-videos' shortcode in all versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wi...

CVSS:
6.4
Affected:
up to 2.9.9
Fixed in:
3.0.0
Disclosed:
Oct 22, 2024

CVE-2024-9836 on NVD →

RSS Feed Widget <= 3.0.0 - Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI']

medium

The RSS Feed Widget plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI'] in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 3.0.0
Fixed in:
3.0.1
Disclosed:
Oct 22, 2024

CVE-2024-9835 on NVD →

RSS Feed Widget [rss-feed-widget] < 3.0.0

unknown

[en] The RSS Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rfw-youtube-videos shortcode in all versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Oct 18, 2024

CVE-2024-10057 on NVD →

RSS Feed Widget <= 2.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via rfw-youtube-videos Shortcode

medium

The RSS Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rfw-youtube-videos shortcode in all versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 2.9.9
Fixed in:
3.0.0
Disclosed:
Oct 17, 2024

CVE-2024-10057 on NVD →

RSS Feed Widget [rss-feed-widget] < 2.9.8

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood RSS Feed Widget allows Stored XSS.This issue affects RSS Feed Widget: from n/a through 2.9.7.

Affected:
up to 2.9.8
Fixed in:
2.9.8
Disclosed:
Apr 22, 2024

CVE-2024-32690 on NVD →

RSS Feed Widget <= 2.9.7 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The RSS Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject a...

CVSS:
4.4
Affected:
up to 2.9.7
Fixed in:
2.9.8
Disclosed:
Apr 19, 2024

CVE-2024-32690 on NVD →

RSS Feed Widget [rss-feed-widget] < 2.8.1

unknown

[en] Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.

Affected:
up to 2.8.1
Fixed in:
2.8.1
Disclosed:
Aug 26, 2020

CVE-2020-24314 on NVD →

RSS Feed Widget [rss-feed-widget] < 2.8.1

unknown

Authenticated Cross-Site Scripting (XSS) vulnerability found by zerodetail & ratherbland in WordPress RSS Feed Widget plugin (versions <= 2.8.0).

Affected:
up to 2.8.1
Fixed in:
2.8.1
Disclosed:
Aug 26, 2020

RSS Feed Widget <= 2.8.0 - Reflected Cross-Site Scripting

medium

Fahad Mahmood RSS Feed Widget Plugin v2.8.0 and lower does not sanitize the value of the "t" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.

CVSS:
6.1
Affected:
up to 2.8.1
Fixed in:
2.8.1
Disclosed:
Aug 10, 2020

CVE-2020-24314 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database