WordPress RSS Aggregator < 4.20 - Authenticated Cross-Site Scripting
WordPress RSS Aggregator < 4.20 is susceptible to cross-site scripting. The plugin does not sanitize and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to reflected cross-site scripting.
wp_rss_aggregatorPoC 已收录
CVSS6.1EPSS 2.8%