plugin

Wp Rss Aggregator Vulnerabilities

25 known security issues reported for the Wp Rss Aggregator WordPress plugin. Most recent disclosed Mar 9, 2026.

2 high 11 medium 1 low

Running Wp Rss Aggregator on your site? Check whether your installed version is affected.

Scan your site free

WP RSS Aggregator - WordPress RSS Aggregator - RSS Import, News Feeds, Feed to Post, and Autoblogging plugin <= 5.0.11 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage vulnerability

high

WordPress RSS Aggregator - RSS Import, News Feeds, Feed to Post, and Autoblogging plugin <= 5.0.11 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage vulnerability

CVSS:
7.1
Affected:
up to 5.0.11
Fixed in:
5.0.12
Disclosed:
Mar 9, 2026

RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.11 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage

medium

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via postMessage in all versions up to, and including, 5.0.11. This is due to the plugin's admin-shell.js registering a global message event listener without origin validation...

CVSS:
6.1
Affected:
up to 5.0.11
Fixed in:
5.0.12
Disclosed:
Mar 6, 2026

CVE-2026-2433 on NVD →

RSS Aggregator <= 5.0.10 - Reflected Cross-Site Scripting via 'template' Parameter

high

The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for unauthenticated attackers to inject arbitra...

CVSS:
7.2
Affected:
up to 5.0.10
Fixed in:
5.0.11
Disclosed:
Feb 16, 2026

CVE-2026-1216 on NVD →

RSS Aggregator &#8211; RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 5.0.11

unknown

[en] The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-rss-aggregator' shortcode in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attri...

Affected:
up to 5.0.11
Fixed in:
5.0.11
Disclosed:
Jan 23, 2026

CVE-2025-14745 on NVD →

RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via wp-rss-aggregator Shortcode

medium

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-rss-aggregator' shortcode in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attributes...

CVSS:
6.4
Affected:
up to 5.0.10
Fixed in:
5.0.11
Disclosed:
Jan 22, 2026

CVE-2025-14745 on NVD →

RSS Aggregator &#8211; RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 5.0.11

unknown

[en] The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthen...

Affected:
up to 5.0.11
Fixed in:
5.0.11
Disclosed:
Jan 16, 2026

CVE-2025-14375 on NVD →

RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via className

medium

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...

CVSS:
6.1
Affected:
up to 5.0.10
Fixed in:
5.0.11
Disclosed:
Jan 15, 2026

CVE-2025-14375 on NVD →

RSS Aggregator &#8211; RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.23.13

unknown

[en] The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticat...

Affected:
up to 4.23.13
Fixed in:
4.23.13
Disclosed:
Oct 23, 2024

CVE-2024-9583 on NVD →

RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.12 - Missing Authorization

medium

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated at...

CVSS:
4.3
Affected:
up to 4.23.12
Fixed in:
4.23.13
Disclosed:
Oct 22, 2024

CVE-2024-9583 on NVD →

RSS Aggregator &#8211; RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.23.12

unknown

[en] The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wprss_activate_feed_source' and 'wprss_pause_feed_source' functions in all versions up to, and including, 4.23.11. This makes...

Affected:
up to 4.23.12
Fixed in:
4.23.12
Disclosed:
Jul 16, 2024

CVE-2024-6621 on NVD →

WP RSS Aggregator <= 4.23.11 - Missing Authorization to Authenticated (Subscriber+) Feed State Update

medium

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wprss_activate_feed_source' and 'wprss_pause_feed_source' functions in all versions up to, and including, 4.23.11. This makes it p...

CVSS:
4.3
Affected:
up to 4.23.11
Fixed in:
4.23.12
Disclosed:
Jul 15, 2024

CVE-2024-6621 on NVD →

RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.8 - Reflected Cross-Site Scripting

medium

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'notice_id' parameter in all versions up to, and including, 4.23.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...

CVSS:
6.1
Affected:
up to 4.23.8
Fixed in:
4.23.9
Disclosed:
May 14, 2024

CVE-2024-4860 on NVD →

RSS Aggregator &#8211; RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.23.9

unknown

[en] The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the  'notice_id'  GET parameter.

Affected:
up to 4.23.9
Fixed in:
4.23.9
Disclosed:
May 14, 2024

CVE-2024-4860 on NVD →

RSS Aggregator &#8211; RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.23.6

unknown

[en] The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations...

Affected:
up to 4.23.6
Fixed in:
4.23.6
Disclosed:
Feb 7, 2024

CVE-2024-0628 on NVD →

WP RSS Aggregator <= 4.23.5 - Authenticated (Admin+) Server-Side Request Forgery via RSS Feed Source

low

The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations origi...

CVSS:
3.8
Affected:
4.23.5 – 4.23.5
Fixed in:
4.23.6
Disclosed:
Feb 6, 2024

CVE-2024-0628 on NVD →

RSS Aggregator &#8211; RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.23.5

unknown

[en] The WP RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the RSS feed source in all versions up to, and including, 4.23.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arb...

Affected:
up to 4.23.5
Fixed in:
4.23.5
Disclosed:
Feb 5, 2024

CVE-2024-0630 on NVD →

WP RSS Aggregator <= 4.23.4 - Authenticated (Admin+) Stored Cross-Site Scripting via RSS Feed Source

medium

The WP RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the RSS feed source in all versions up to, and including, 4.23.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrar...

CVSS:
4.4
Affected:
up to 4.23.4
Fixed in:
4.23.5
Disclosed:
Jan 25, 2024

CVE-2024-0630 on NVD →

RSS Aggregator &#8211; RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.20

unknown

[en] The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting

Affected:
up to 4.20
Fixed in:
4.20
Disclosed:
Feb 28, 2022

CVE-2022-0189 on NVD →

WP RSS Aggregator <= 4.19.3 - Reflected Cross-Site Scripting

medium

The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 4.19.3
Fixed in:
4.20
Disclosed:
Jan 26, 2022

CVE-2022-0189 on NVD →

RSS Aggregator &#8211; RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.20

unknown

[en] The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks, allowing any authenticated users, such as s...

Affected:
up to 4.20
Fixed in:
4.20
Disclosed:
Dec 27, 2021

CVE-2021-24988 on NVD →

WP RSS Aggregator <= 4.19.2 - Subscriber+ Stored Cross-Site Scripting

medium

The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks, allowing any authenticated users, such as subscr...

CVSS:
5.4
Affected:
up to 4.19.3
Fixed in:
4.19.3
Disclosed:
Nov 29, 2021

CVE-2021-24988 on NVD →

RSS Aggregator &#8211; RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.20

unknown

[en] The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.

Affected:
up to 4.20
Fixed in:
4.20
Disclosed:
Nov 29, 2021

CVE-2021-24768 on NVD →

WP RSS Aggregator <= 4.19.1 - Admin+ Stored Cross-Site Scripting

medium

The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.

CVSS:
4.8
Affected:
up to 4.19.1
Fixed in:
4.19.2
Disclosed:
Nov 1, 2021

CVE-2021-24768 on NVD →

WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More <= 4.6.3 - Authorization Bypass

medium

The WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wprss_check_if_blacklist_delete() function in versions up to, and including, 4.6.3. This makes it possible for unauthenticated attackers to d...

CVSS:
6.5
Affected:
up to 4.6.3
Fixed in:
4.6.4
Disclosed:
Dec 16, 2014

RSS Aggregator &#8211; RSS Import, News Feeds, Feed to Post, and Autoblogging [wp-rss-aggregator] < 4.6.4

unknown

The WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wprss_check_if_blacklist_delete() function in versions up to, and including, 4.6.3. This makes it possible for unauthenticated attackers to d...

Affected:
up to 4.6.4
Fixed in:
4.6.4
Disclosed:
Dec 16, 2014

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database