CVE Database /
CVE-2022-0189
CVE · Medium
CVE-2022-0189 — WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.20
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-0189
|
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.20 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 4.20
|
4.20 |
2022-01-26 |
—
|
CVE-2022-0189
The WP RSS Aggregator plugin in versions prior to 4.20 contains a reflected cross-site scripting vulnerability in its wprss_fetch_items_row_action AJAX action, where user input from the id parameter is returned to the response without proper sanitization and escaping.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings