Extension WordPress

Vulnérabilités WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

Cette page rassemble les failles publiées pour WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content, leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
0Critiques
13Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

13 fiches

CVE-2026-2433 Moyenne · 6,1
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.11 – Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via postMessage in all versions up to, and including, 5.0.11. This is due to the plugin's…

Versions affectées

*-5.0.11

Correctif

5.0.12

Publication

06/03/2026

CVE-2026-1216 Élevée · 7,2
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

RSS Aggregator <= 5.0.10 – Reflected Cross-Site Scripting via 'template' Parameter

The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

Versions affectées

*-5.0.10

Correctif

5.0.11

Publication

16/02/2026

CVE-2025-14745 Moyenne · 6,4
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 – Authenticated (Contributor+) Stored Cross-Site Scripting via wp-rss-aggregator Shortcode

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-rss-aggregator' shortcode in all versions up to, and including, 5.0.10 due to insufficient…

Versions affectées

*-5.0.10

Correctif

5.0.11

Publication

22/01/2026

CVE-2025-14375 Moyenne · 6,1
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 – Reflected Cross-Site Scripting via className

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 5.0.10 due to insufficient input…

Versions affectées

*-5.0.10

Correctif

5.0.11

Publication

15/01/2026

CVE-2024-9583 Moyenne · 4,3
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.12 – Missing Authorization

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to,…

Versions affectées

*-4.23.12

Correctif

4.23.13

Publication

22/10/2024

CVE-2024-6621 Moyenne · 4,3
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

WP RSS Aggregator <= 4.23.11 – Missing Authorization to Authenticated (Subscriber+) Feed State Update

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wprss_activate_feed_source' and 'wprss_pause_feed_source' functions in all versions…

Versions affectées

*-4.23.11

Correctif

4.23.12

Publication

15/07/2024

CVE-2024-4860 Moyenne · 6,1
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.8 – Reflected Cross-Site Scripting

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'notice_id' parameter in all versions up to, and including, 4.23.8 due to insufficient input…

Versions affectées

*-4.23.8

Correctif

4.23.9

Publication

14/05/2024

CVE-2024-0628 Faible · 3,8
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

WP RSS Aggregator <= 4.23.5 – Authenticated (Admin+) Server-Side Request Forgery via RSS Feed Source

The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. This makes it possible for authenticated attackers, with administrator-level…

Versions affectées

4.23.5

Correctif

4.23.6

Publication

06/02/2024

CVE-2024-0630 Moyenne · 4,4
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

WP RSS Aggregator <= 4.23.4 – Authenticated (Admin+) Stored Cross-Site Scripting via RSS Feed Source

The WP RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the RSS feed source in all versions up to, and including, 4.23.4 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-4.23.4

Correctif

4.23.5

Publication

25/01/2024

CVE-2021-24988 Moyenne · 5,4
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

WP RSS Aggregator <= 4.19.2 – Subscriber+ Stored Cross-Site Scripting

The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing…

Versions affectées

[*, 4.19.3)

Correctif

4.19.3

Publication

29/11/2021

CVE-2021-24768 Moyenne · 4,8
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

WP RSS Aggregator <= 4.19.1 – Admin+ Stored Cross-Site Scripting

The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could…

Versions affectées

*-4.19.1

Correctif

4.19.2

Publication

01/11/2021

Vulnérabilité Moyenne · 6,5
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content

WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More <= 4.6.3 – Authorization Bypass

The WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wprss_check_if_blacklist_delete() function in versions up to, and including, 4.6.3.…

Versions affectées

*-4.6.3

Correctif

4.6.4

Publication

16/12/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités