CVE-2026-1216
- EPSS 0.12%
- Veröffentlicht 17.02.2026 09:26:22
- Zuletzt bearbeitet 18.02.2026 17:52:22
The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. ...
CVE-2025-14745
- EPSS 0.01%
- Veröffentlicht 23.01.2026 05:29:51
- Zuletzt bearbeitet 26.01.2026 15:03:51
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-rss-aggregator' shortcode in all versions up to, and including, 5.0.10 due to insuffici...
CVE-2025-14375
- EPSS 0.12%
- Veröffentlicht 16.01.2026 07:23:09
- Zuletzt bearbeitet 16.01.2026 15:55:12
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 5.0.10 due to insufficient input sani...
CVE-2024-9583
- EPSS 0.18%
- Veröffentlicht 23.10.2024 07:15:03
- Zuletzt bearbeitet 25.10.2024 16:28:17
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up t...
CVE-2024-6621
- EPSS 0.17%
- Veröffentlicht 16.07.2024 11:15:10
- Zuletzt bearbeitet 21.11.2024 09:50:01
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wprss_activate_feed_source' and 'wprss_pause_feed_source' fu...
CVE-2024-4860
- EPSS 0.25%
- Veröffentlicht 14.05.2024 16:17:36
- Zuletzt bearbeitet 25.03.2025 17:50:50
The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the 'notice_id' GET parameter.