Vulnerability Details CVE-2024-6621
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wprss_activate_feed_source' and 'wprss_pause_feed_source' functions in all versions up to, and including, 4.23.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate or pause existing RSS feeds.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.6%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2024-6621
-
cpe:2.3:a:rebelcode:rss_aggregator:-
-
cpe:2.3:a:rebelcode:rss_aggregator:4.12.1
-
cpe:2.3:a:rebelcode:rss_aggregator:4.12.2
-
cpe:2.3:a:rebelcode:rss_aggregator:4.12.3
-
cpe:2.3:a:rebelcode:rss_aggregator:4.13
-
cpe:2.3:a:rebelcode:rss_aggregator:4.13.1
-
cpe:2.3:a:rebelcode:rss_aggregator:4.13.2
-
cpe:2.3:a:rebelcode:rss_aggregator:4.14
-
cpe:2.3:a:rebelcode:rss_aggregator:4.15
-
cpe:2.3:a:rebelcode:rss_aggregator:4.15.1
-
cpe:2.3:a:rebelcode:rss_aggregator:4.15.2
-
cpe:2.3:a:rebelcode:rss_aggregator:4.16
-
cpe:2.3:a:rebelcode:rss_aggregator:4.17
-
cpe:2.3:a:rebelcode:rss_aggregator:4.17.1
-
cpe:2.3:a:rebelcode:rss_aggregator:4.17.10
-
cpe:2.3:a:rebelcode:rss_aggregator:4.17.2
-
cpe:2.3:a:rebelcode:rss_aggregator:4.17.3
-
cpe:2.3:a:rebelcode:rss_aggregator:4.17.4
-
cpe:2.3:a:rebelcode:rss_aggregator:4.17.5
-
cpe:2.3:a:rebelcode:rss_aggregator:4.17.6
-
cpe:2.3:a:rebelcode:rss_aggregator:4.17.7
-
cpe:2.3:a:rebelcode:rss_aggregator:4.17.8
-
cpe:2.3:a:rebelcode:rss_aggregator:4.17.9
-
cpe:2.3:a:rebelcode:rss_aggregator:4.18
-
cpe:2.3:a:rebelcode:rss_aggregator:4.18.1
-
cpe:2.3:a:rebelcode:rss_aggregator:4.18.2
-
cpe:2.3:a:rebelcode:rss_aggregator:4.19
-
cpe:2.3:a:rebelcode:rss_aggregator:4.19.1
-
cpe:2.3:a:rebelcode:rss_aggregator:4.19.2
-
cpe:2.3:a:rebelcode:rss_aggregator:4.19.3
-
cpe:2.3:a:rebelcode:rss_aggregator:4.20
-
cpe:2.3:a:rebelcode:rss_aggregator:4.21
-
cpe:2.3:a:rebelcode:rss_aggregator:4.21.1
-
cpe:2.3:a:rebelcode:rss_aggregator:4.22.1
-
cpe:2.3:a:rebelcode:rss_aggregator:4.22.2
-
cpe:2.3:a:rebelcode:rss_aggregator:4.22.3
-
cpe:2.3:a:rebelcode:rss_aggregator:4.22.4
-
cpe:2.3:a:rebelcode:rss_aggregator:4.23
-
cpe:2.3:a:rebelcode:rss_aggregator:4.23.1
-
cpe:2.3:a:rebelcode:rss_aggregator:4.23.10
-
cpe:2.3:a:rebelcode:rss_aggregator:4.23.11
-
cpe:2.3:a:rebelcode:rss_aggregator:4.23.2
-
cpe:2.3:a:rebelcode:rss_aggregator:4.23.3
-
cpe:2.3:a:rebelcode:rss_aggregator:4.23.4
-
cpe:2.3:a:rebelcode:rss_aggregator:4.23.5
-
cpe:2.3:a:rebelcode:rss_aggregator:4.23.6
-
cpe:2.3:a:rebelcode:rss_aggregator:4.23.7
-
cpe:2.3:a:rebelcode:rss_aggregator:4.23.8
-
cpe:2.3:a:rebelcode:rss_aggregator:4.23.9