Impact
The RSS Aggregator by Feedzy plugin for WordPress contains a stored cross‑site scripting flaw (CWE‑79) caused by insufficient sanitization of the ‘aspectRatio’ attribute in feed items. Authenticated users who hold contributor or higher permissions can inject arbitrary JavaScript that is stored in the database and executed whenever a visitor loads a page containing the injected feed entry. This can lead to client‑side attacks such as session hijacking, defacement, or malicious redirects.
Affected Systems
All installations of Themeisle’s RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin with any version up to and including 5.2.1 are affected.
Risk and Exploitability
The vulnerability is scored 6.4 on CVSS, indicating moderate severity, and the EPSS score of less than 1 % suggests exploitation is not highly likely at present and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must first authenticate with contributor‑level or higher permissions in order to edit feed items; once the malicious script is stored, it will run in the browsers of any user who views the affected page.
OpenCVE Enrichment