cleantalk
Vulnerabilities and Security Researches

WP RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging, CVE-2021-24768

CVE, Research URL

CVE-2021-24768

Published on
Nov 29, 2021
Research Description
The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.
Affected versions
max 4.6.4.
Status
vulnerable