Extension WordPress
Vulnérabilités WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content
Cette page rassemble les failles publiées pour WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content
13 fiches
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.11 – Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via postMessage in all versions up to, and including, 5.0.11. This is due to the plugin's…
*-5.0.11
5.0.12
06/03/2026
RSS Aggregator <= 5.0.10 – Reflected Cross-Site Scripting via 'template' Parameter
The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-5.0.10
5.0.11
16/02/2026
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 – Authenticated (Contributor+) Stored Cross-Site Scripting via wp-rss-aggregator Shortcode
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-rss-aggregator' shortcode in all versions up to, and including, 5.0.10 due to insufficient…
*-5.0.10
5.0.11
22/01/2026
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 – Reflected Cross-Site Scripting via className
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 5.0.10 due to insufficient input…
*-5.0.10
5.0.11
15/01/2026
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.12 – Missing Authorization
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to,…
*-4.23.12
4.23.13
22/10/2024
WP RSS Aggregator <= 4.23.11 – Missing Authorization to Authenticated (Subscriber+) Feed State Update
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wprss_activate_feed_source' and 'wprss_pause_feed_source' functions in all versions…
*-4.23.11
4.23.12
15/07/2024
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.8 – Reflected Cross-Site Scripting
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'notice_id' parameter in all versions up to, and including, 4.23.8 due to insufficient input…
*-4.23.8
4.23.9
14/05/2024
WP RSS Aggregator <= 4.23.5 – Authenticated (Admin+) Server-Side Request Forgery via RSS Feed Source
The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. This makes it possible for authenticated attackers, with administrator-level…
4.23.5
4.23.6
06/02/2024
WP RSS Aggregator <= 4.23.4 – Authenticated (Admin+) Stored Cross-Site Scripting via RSS Feed Source
The WP RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the RSS feed source in all versions up to, and including, 4.23.4 due to insufficient input sanitization and output escaping. This makes it possible…
*-4.23.4
4.23.5
25/01/2024
WP RSS Aggregator <= 4.19.3 – Reflected Cross-Site Scripting
The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting
*-4.19.3
4.20
26/01/2022
WP RSS Aggregator <= 4.19.2 – Subscriber+ Stored Cross-Site Scripting
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing…
[*, 4.19.3)
4.19.3
29/11/2021
WP RSS Aggregator <= 4.19.1 – Admin+ Stored Cross-Site Scripting
The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could…
*-4.19.1
4.19.2
01/11/2021
WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More <= 4.6.3 – Authorization Bypass
The WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wprss_check_if_blacklist_delete() function in versions up to, and including, 4.6.3.…
*-4.6.3
4.6.4
16/12/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.