Wprssaggregator

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    4
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-0628

    The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Last Modified: Nov 21, 2024
    Published: Feb 07, 2024

    CVE-2024-0630

    WP RSS Aggregator <= 4.23.4 - Authenticated (Admin+) Stored Cross-Site Scripting via RSS Feed Source

    Last Modified: Apr 08, 2026
    Published: Feb 05, 2024

    CVE-2022-0189

    WP RSS Aggregator < 4.20 - Reflected Cross-Site Scripting (XSS)

    Last Modified: Nov 21, 2024
    Published: Feb 28, 2022

    CVE-2021-24988

    WP RSS Aggregator < 4.19.3 - Subscriber+ Stored Cross-Site Scripting

    Last Modified: Nov 21, 2024
    Published: Dec 27, 2021

    CVE-2021-24768

    WP RSS Aggregator < 4.19.2 - Admin+ Stored Cross-Site Scripting

    Last Modified: Nov 21, 2024
    Published: Nov 29, 2021
    Items Per Page
    Wprssaggregator Vulnerabilities & Security CVEs | CVE-DB