CVE-2024-0628: Wprssaggregator Wp Rss Aggregator
Low severity, CVSS 3.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected products
- Wprssaggregator Wp Rss Aggregator: up to and including 4.23.5
Published 2024-02-07. Last modified 2026-06-17.