The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send premium support requests with an attacker-controlled subject line and email address to support allowing them to impersonate the site owner. License information may also be leaked.
History

Fri, 25 Oct 2024 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:rebelcode:rss_aggregator:*:*:*:*:*:wordpress:*:*

Wed, 23 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Rebelcode
Rebelcode rss Aggregator
CPEs cpe:2.3:a:rebelcode:rss_aggregator:-:*:*:*:*:wordpress:*:*
Vendors & Products Rebelcode
Rebelcode rss Aggregator
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Oct 2024 07:00:00 +0000

Type Values Removed Values Added
Description The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send premium support requests with an attacker-controlled subject line and email address to support allowing them to impersonate the site owner. License information may also be leaked.
Title RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.12 - Missing Authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-10-23T06:45:05.657Z

Updated: 2024-10-23T13:31:48.353Z

Reserved: 2024-10-07T15:36:07.784Z

Link: CVE-2024-9583

cve-icon Vulnrichment

Updated: 2024-10-23T13:31:41.362Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-23T07:15:03.283

Modified: 2024-10-25T16:28:17.497

Link: CVE-2024-9583

cve-icon Redhat

No data.