VYPR

Wpematico Rss Feed Fetcher

by Etruel

CVEs (1)

  • CVE-2021-24793MedNov 1, 2021
    risk 0.31cvss 4.8epss 0.01

    The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.