CVE · Medium

CVE-2022-0189 — WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.20

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0189 WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 4.20 4.20 2022-01-26

CVE-2022-0189

The WP RSS Aggregator plugin in versions prior to 4.20 contains a reflected cross-site scripting vulnerability in its wprss_fetch_items_row_action AJAX action, where user input from the id parameter is returned to the response without proper sanitization and escaping.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.