First published: Mon Jan 30 2023(Updated: )
The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Feedzy RSS Aggregator | <4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-4667.
The severity of CVE-2022-4667 is medium with a CVSS score of 5.4.
The affected software for CVE-2022-4667 is the RSS Aggregator by Feedzy WordPress plugin before version 4.1.1.
CVE-2022-4667 could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
To fix CVE-2022-4667, update the RSS Aggregator by Feedzy WordPress plugin to version 4.1.1 or later.