Impact
The RSS Aggregator by Feedzy WordPress plugin contains a stored cross‑site scripting flaw (CWE‑79) that stems from insufficient sanitization of the ‘aspectRatio’ attribute used in feed items. Authenticated users with contributor‑level permissions or higher can inject arbitrary JavaScript that will be stored in the database and executed whenever a visitor loads a page containing the injected feed entry. This can lead to client‑side attacks such as session hijacking, defacement, or malicious redirects.
Affected Systems
All installations of Themeisle’s RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin with versions up to and including 5.2.1.
Risk and Exploitability
The vulnerability is scored 6.4 on CVSS, indicating moderate severity. The EPSS score of less than 1 % suggests exploitation is not highly likely, and the issue is not listed in the CISA KEV catalog. Exploitation requires that the attacker be able to authenticate with contributor or higher privileges to edit feed items; once the malicious script is stored, it will run in the browsers of all users who view the affected pages.
OpenCVE Enrichment