CVE-2024-4860

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-4860
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-4860.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-4860
Published
2024-05-14T16:17:36Z
Modified
2025-03-26T01:54:24.872985Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the  'notice_id'  GET parameter.

References

Affected packages

Git / github.com/rebelcode/wp-rss-aggregator

Affected ranges

Type
GIT
Repo
https://github.com/rebelcode/wp-rss-aggregator
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

4.*

4.19.1
4.19.2
4.19.3
4.20
4.23.3

v4.*

v4.12.1
v4.12.2
v4.12.3
v4.13
v4.13.1
v4.13.2
v4.14
v4.15
v4.15.1
v4.15.2
v4.16
v4.17
v4.17.1
v4.17.10
v4.17.2
v4.17.3
v4.17.4
v4.17.5
v4.17.6
v4.17.7
v4.17.8
v4.17.9
v4.18
v4.18.1
v4.18.2
v4.19
v4.21
v4.21.1
v4.22.1
v4.22.2
v4.22.3
v4.22.4
v4.23
v4.23.1
v4.23.2
v4.23.4
v4.23.5
v4.23.6
v4.23.7