PLUGIN SECURITY

Is Wp Rss Aggregator safe?

The #1 WordPress RSS aggregator to quickly import RSS feeds, build a news aggregator, and for easy autoblogging.

What this plugin does

  • Slug: wp-rss-aggregator
  • Author: RebelCode
  • 40000+ active installs
  • 90/100 rating (562 reviews on wordpress.org)
  • 3453882 all-time downloads
  • On WordPress.org since 2012-01-05

autobloggingfeed to postnews aggregatorNews Feedrss aggregator

Maintenance status

  • Latest known version: 5.3.0
  • Last updated: 2026-08-24 11:30am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4.0+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

12 known CVEs on file for Wp Rss Aggregator.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14745 WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 5.0.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.0.11 5.0.11 2026-01-22 ✓ fixed in latest
CVE-2025-14375 WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 5.0.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.0.11 5.0.11 2026-01-15 ✓ fixed in latest
CVE-2024-9583 WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.23.13 Missing Authorization Medium 5.4 < 4.23.13 4.23.13 2024-10-22 ✓ fixed in latest
CVE-2024-6621 WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.23.12 Missing Authorization Medium 4.3 < 4.23.12 4.23.12 2024-07-15 ✓ fixed in latest
CVE-2024-4860 WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.23.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 4.23.9 4.23.9 2024-05-14 ✓ fixed in latest
CVE-2024-0628 WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.23.6 Server-Side Request Forgery (SSRF) Low 3.8 < 4.23.6 4.23.6 2024-02-06 ✓ fixed in latest
CVE-2024-0630 WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.23.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.23.5 4.23.5 2024-01-25 ✓ fixed in latest
CVE-2022-0189 WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 4.20 4.20 2022-01-26 ✓ fixed in latest
+ 7 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24988 WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.20 4.20 2021-11-29 ✓ fixed in latest
CVE-2021-24768 WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.20 4.20 2021-11-01 ✓ fixed in latest
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 4.6.4 Unknown < 4.6.4 4.6.4 2014-12-16 ✓ fixed in latest
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 5.0.12 Unknown < 5.0.12 5.0.12 0000-00-00 ✓ fixed in latest
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 5.0.11 Unknown < 5.0.11 5.0.11 0000-00-00 ✓ fixed in latest
CVE-2026-1216 RSS Aggregator < 5.0.11 - Reflected Cross-Site Scripting via 'template' Parameter Unknown < 5.0.11 5.0.11 ✓ fixed in latest
CVE-2026-2433 RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging < 5.0.12 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage Unknown < 5.0.12 5.0.12 ✓ fixed in latest

How to fix it

Keep Wp Rss Aggregator updated — 5.3.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.