Skip to content

Known CVE

WordPress RSS Aggregator < 4.20 - Authenticated Cross-Site Scripting

WordPress RSS Aggregator < 4.20 is susceptible to cross-site scripting. The plugin does not sanitize and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to reflected cross-site scripting.

CVE-2022-0189

Medium2022CVSS 6.1CWE-79

cve2022 · wpscan · wordpress · xss · wp-plugin · authenticated · wprssaggregator · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website