CVE · Medium

CVE-2024-4860 — WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.23.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4860 WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.23.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 4.23.9 4.23.9 2024-05-14

CVE-2024-4860

The WP RSS Aggregator plugin through version 4.23.8 contains a reflected cross-site scripting vulnerability in the 'notice_id' parameter caused by inadequate sanitization and escaping of user input. An unauthenticated attacker can craft a malicious link containing arbitrary JavaScript that executes in a user's browser when clicked, potentially allowing session hijacking or credential theft. The vulnerability affects all installations running version 4.23.8 or earlier.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.