CVE-2023-6877

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Apr 7, 2024
Updated: Jan 14, 2025
CWE ID 79

Summary

CVE-2023-6877: The WordPress plugin "Feedzy – Feed to Post" version 4.3.3 and below, used for RSS feed aggregation, is susceptible to Stored Cross-Site Scripting (XSS). Attackers with contributor access or higher can exploit insufficient input sanitization and output escaping on error messages' Content-Type field, leading to the injection of malicious web scripts. These scripts will execute when users access the affected pages.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share