CVE-2021-24768: vulnerability in WP RSS Aggregator – News Feeds, Autoblogging…
WP RSS Aggregator < 4.19.2 - Admin+ Stored Cross-Site Scripting
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.6%
exploitation probability
0.6%top 52% of all CVEs
observed exploitation
nono source reports it
The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.
Affected products
Unknown · WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and MoreRelated CVEs — WP RSS Aggregator – News Feeds, Autoblogging…
In the same product, most dangerous first.