The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send premium support requests with an attacker-controlled subject line and email address to support allowing them to impersonate the site owner. License information may also be leaked.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 25 Oct 2024 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:rebelcode:rss_aggregator:*:*:*:*:*:wordpress:*:*

Wed, 23 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Rebelcode
Rebelcode rss Aggregator
CPEs cpe:2.3:a:rebelcode:rss_aggregator:-:*:*:*:*:wordpress:*:*
Vendors & Products Rebelcode
Rebelcode rss Aggregator
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Oct 2024 07:00:00 +0000

Type Values Removed Values Added
Description The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send premium support requests with an attacker-controlled subject line and email address to support allowing them to impersonate the site owner. License information may also be leaked.
Title RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.12 - Missing Authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-10-23T13:31:48.353Z

Reserved: 2024-10-07T15:36:07.784Z

Link: CVE-2024-9583

cve-icon Vulnrichment

Updated: 2024-10-23T13:31:41.362Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-23T07:15:03.283

Modified: 2024-10-25T16:28:17.497

Link: CVE-2024-9583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.