CVE-2023-6877
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Apr 7, 2024
Updated: Jan 14, 2025
CWE ID 79
Summary
CVE-2023-6877: The WordPress plugin "Feedzy – Feed to Post" version 4.3.3 and below, used for RSS feed aggregation, is susceptible to Stored Cross-Site Scripting (XSS). Attackers with contributor access or higher can exploit insufficient input sanitization and output escaping on error messages' Content-Type field, leading to the injection of malicious web scripts. These scripts will execute when users access the affected pages.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share