Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High1
Medium3
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2026-04-15

CVE-2026-1216 - Rss Aggregator Plugin

The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Rss Aggregator

CVE-2026-1216

HIGH CVSS 7.2 2026-02-17
Threat Entry Updated 2024-10-25

CVE-2024-9583 - Rss Aggregator Plugin

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send premium support requests with an attacker-controlled subject line and email address to support allowing them to impersonate the site owner. License information may also be leaked.

PLUGIN Rss Aggregator

CVE-2024-9583

MEDIUM CVSS 4.3 2024-10-23
Threat Entry Updated 2024-11-21

CVE-2024-6621 - Rss Aggregator Plugin

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wprss_activate_feed_source' and 'wprss_pause_feed_source' functions in all versions up to, and including, 4.23.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate or pause existing RSS feeds.

PLUGIN Rss Aggregator

CVE-2024-6621

MEDIUM CVSS 4.3 2024-07-16
Threat Entry Updated 2025-03-25

CVE-2024-4860 - Rss Aggregator Plugin

The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the  'notice_id'  GET parameter.

PLUGIN Rss Aggregator

CVE-2024-4860

MEDIUM CVSS 5.4 2024-05-14
Scroll to top