CVE-2021-24768CWE-79

CVE-2021-24768: vulnerability in WP RSS Aggregator – News Feeds, Autoblogging…

WP RSS Aggregator < 4.19.2 - Admin+ Stored Cross-Site Scripting

Published · Updated

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.6%
exploitation probability
0.6%top 52% of all CVEs
observed exploitation
nono source reports it
The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.