WP RSS Aggregator is a WordPress plugin focused on feed aggregation and content syndication, presenting a web-application attack surface centered on the plugin's input handling and request processing. Its observed vulnerability pattern clusters around input sanitization, authorization controls, and cross-site protections, including cross-site scripting, cross-site request forgery, missing authorization checks, and server-side request forgery—weaknesses typical of WordPress plugins that bridge external data ingestion with administrative functionality. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wprssaggregator over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0189MEDIUM The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the re | Feb 28, 2022 | 6.1 | 32 | NO | YES |
CVE-2021-24988MEDIUM The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS iss | Dec 27, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-24768MEDIUM The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege user | Nov 29, 2021 | 4.8 | 18 | NO | NO |
CVE-2024-0630MEDIUM The WP RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the RSS feed source in all versions up to, and including, 4.23.4 due to insufficient inp | Feb 5, 2024 | 4.8 | 17 | NO | NO |
The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. This | Feb 7, 2024 | 3.8 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wprssaggregator.
Media articles that mention a CVE ID that affects a product developed by Wprssaggregator — matched by CVE ID, not by vendor name.