CVE · Medium

CVE-2023-6801 — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.3.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6801 RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 4.3.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.3.3 4.3.3 2024-01-05

CVE-2023-6801

The RSS Aggregator by Feedzy plugin before version 4.3.3 contains a cross-site scripting vulnerability that Colin Xu discovered, enabling attackers to inject harmful scripts into websites that execute when visitors access affected pages. These injected scripts could redirect users, display unwanted advertisements, or execute arbitrary HTML payloads. The flaw has been patched in version 4.3.3 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.