WP RSS Aggregator - WordPress RSS Aggregator - RSS Import, News Feeds, Feed to Post, and Autoblogging plugin <= 5.0.11 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage vulnerability
high
WordPress RSS Aggregator - RSS Import, News Feeds, Feed to Post, and Autoblogging plugin <= 5.0.11 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage vulnerability
- CVSS:
- 7.1
- Affected:
- up to 5.0.11
- Fixed in:
- 5.0.12
- Disclosed:
- Mar 9, 2026
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.11 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage
medium
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via postMessage in all versions up to, and including, 5.0.11. This is due to the plugin's admin-shell.js registering a global message event listener without origin validation...
- CVSS:
- 6.1
- Affected:
- up to 5.0.11
- Fixed in:
- 5.0.12
- Disclosed:
- Mar 6, 2026
CVE-2026-2433 on NVD →
RSS Aggregator <= 5.0.10 - Reflected Cross-Site Scripting via 'template' Parameter
high
The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for unauthenticated attackers to inject arbitra...
- CVSS:
- 7.2
- Affected:
- up to 5.0.10
- Fixed in:
- 5.0.11
- Disclosed:
- Feb 16, 2026
CVE-2026-1216 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 5.0.11
unknown
[en] The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-rss-aggregator' shortcode in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attri...
- Affected:
- up to 5.0.11
- Fixed in:
- 5.0.11
- Disclosed:
- Jan 23, 2026
CVE-2025-14745 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via wp-rss-aggregator Shortcode
medium
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-rss-aggregator' shortcode in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attributes...
- CVSS:
- 6.4
- Affected:
- up to 5.0.10
- Fixed in:
- 5.0.11
- Disclosed:
- Jan 22, 2026
CVE-2025-14745 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 5.0.11
unknown
[en] The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthen...
- Affected:
- up to 5.0.11
- Fixed in:
- 5.0.11
- Disclosed:
- Jan 16, 2026
CVE-2025-14375 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via className
medium
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...
- CVSS:
- 6.1
- Affected:
- up to 5.0.10
- Fixed in:
- 5.0.11
- Disclosed:
- Jan 15, 2026
CVE-2025-14375 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.23.13
unknown
[en] The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticat...
- Affected:
- up to 4.23.13
- Fixed in:
- 4.23.13
- Disclosed:
- Oct 23, 2024
CVE-2024-9583 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.12 - Missing Authorization
medium
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated at...
- CVSS:
- 4.3
- Affected:
- up to 4.23.12
- Fixed in:
- 4.23.13
- Disclosed:
- Oct 22, 2024
CVE-2024-9583 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.23.12
unknown
[en] The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wprss_activate_feed_source' and 'wprss_pause_feed_source' functions in all versions up to, and including, 4.23.11. This makes...
- Affected:
- up to 4.23.12
- Fixed in:
- 4.23.12
- Disclosed:
- Jul 16, 2024
CVE-2024-6621 on NVD →
WP RSS Aggregator <= 4.23.11 - Missing Authorization to Authenticated (Subscriber+) Feed State Update
medium
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wprss_activate_feed_source' and 'wprss_pause_feed_source' functions in all versions up to, and including, 4.23.11. This makes it p...
- CVSS:
- 4.3
- Affected:
- up to 4.23.11
- Fixed in:
- 4.23.12
- Disclosed:
- Jul 15, 2024
CVE-2024-6621 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.8 - Reflected Cross-Site Scripting
medium
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'notice_id' parameter in all versions up to, and including, 4.23.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...
- CVSS:
- 6.1
- Affected:
- up to 4.23.8
- Fixed in:
- 4.23.9
- Disclosed:
- May 14, 2024
CVE-2024-4860 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.23.9
unknown
[en] The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the 'notice_id' GET parameter.
- Affected:
- up to 4.23.9
- Fixed in:
- 4.23.9
- Disclosed:
- May 14, 2024
CVE-2024-4860 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.23.6
unknown
[en] The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations...
- Affected:
- up to 4.23.6
- Fixed in:
- 4.23.6
- Disclosed:
- Feb 7, 2024
CVE-2024-0628 on NVD →
WP RSS Aggregator <= 4.23.5 - Authenticated (Admin+) Server-Side Request Forgery via RSS Feed Source
low
The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations origi...
- CVSS:
- 3.8
- Affected:
- 4.23.5 – 4.23.5
- Fixed in:
- 4.23.6
- Disclosed:
- Feb 6, 2024
CVE-2024-0628 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.23.5
unknown
[en] The WP RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the RSS feed source in all versions up to, and including, 4.23.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arb...
- Affected:
- up to 4.23.5
- Fixed in:
- 4.23.5
- Disclosed:
- Feb 5, 2024
CVE-2024-0630 on NVD →
WP RSS Aggregator <= 4.23.4 - Authenticated (Admin+) Stored Cross-Site Scripting via RSS Feed Source
medium
The WP RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the RSS feed source in all versions up to, and including, 4.23.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrar...
- CVSS:
- 4.4
- Affected:
- up to 4.23.4
- Fixed in:
- 4.23.5
- Disclosed:
- Jan 25, 2024
CVE-2024-0630 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.20
unknown
[en] The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 4.20
- Fixed in:
- 4.20
- Disclosed:
- Feb 28, 2022
CVE-2022-0189 on NVD →
WP RSS Aggregator <= 4.19.3 - Reflected Cross-Site Scripting
medium
The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 4.19.3
- Fixed in:
- 4.20
- Disclosed:
- Jan 26, 2022
CVE-2022-0189 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.20
unknown
[en] The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks, allowing any authenticated users, such as s...
- Affected:
- up to 4.20
- Fixed in:
- 4.20
- Disclosed:
- Dec 27, 2021
CVE-2021-24988 on NVD →
WP RSS Aggregator <= 4.19.2 - Subscriber+ Stored Cross-Site Scripting
medium
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks, allowing any authenticated users, such as subscr...
- CVSS:
- 5.4
- Affected:
- up to 4.19.3
- Fixed in:
- 4.19.3
- Disclosed:
- Nov 29, 2021
CVE-2021-24988 on NVD →
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.20
unknown
[en] The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.
- Affected:
- up to 4.20
- Fixed in:
- 4.20
- Disclosed:
- Nov 29, 2021
CVE-2021-24768 on NVD →
WP RSS Aggregator <= 4.19.1 - Admin+ Stored Cross-Site Scripting
medium
The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.
- CVSS:
- 4.8
- Affected:
- up to 4.19.1
- Fixed in:
- 4.19.2
- Disclosed:
- Nov 1, 2021
CVE-2021-24768 on NVD →
WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More <= 4.6.3 - Authorization Bypass
medium
The WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wprss_check_if_blacklist_delete() function in versions up to, and including, 4.6.3. This makes it possible for unauthenticated attackers to d...
- CVSS:
- 6.5
- Affected:
- up to 4.6.3
- Fixed in:
- 4.6.4
- Disclosed:
- Dec 16, 2014
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.6.4
unknown
The WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wprss_check_if_blacklist_delete() function in versions up to, and including, 4.6.3. This makes it possible for unauthenticated attackers to d...
- Affected:
- up to 4.6.4
- Fixed in:
- 4.6.4
- Disclosed:
- Dec 16, 2014