VendorsRebelCoderss_aggregatorany version
Vulnerabilities

RebelCode RSS Aggregator any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-4860
The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the  'notice_id'  GET parameter.
Published 2024-05-14 · Analyzed
6.1EPSS 0.004
CVE-2024-9583
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.12 - Missing Authorization
Published 2024-10-23 · Analyzed
5.4EPSS 0.004
CVE-2024-6621
WP RSS Aggregator <= 4.23.11 - Missing Authorization to Authenticated (Subscriber+) Feed State Update
Published 2024-07-16 · Modified
4.3EPSS 0.004