Description
The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the 'notice_id' GET parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-44438 | The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the 'notice_id' GET parameter. |
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2024-16 |
|
History
Tue, 25 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rebelcode
Rebelcode rss Aggregator |
|
| CPEs | cpe:2.3:a:rebelcode:rss_aggregator:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Rebelcode
Rebelcode rss Aggregator |
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-01T20:55:10.115Z
Reserved: 2024-05-14T07:06:02.729Z
Link: CVE-2024-4860
Updated: 2024-08-01T20:55:10.115Z
Status : Analyzed
Published: 2024-05-14T16:17:36.730
Modified: 2025-03-25T17:50:50.723
Link: CVE-2024-4860
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD