CVE-2024-9583

Source
https://cve.org/CVERecord?id=CVE-2024-9583
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-9583.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-9583
Published
2024-10-23T07:15:03.283Z
Modified
2025-11-16T12:10:41.058118Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprssajaxsendpremiumsupport function in all versions up to, and including, 4.23.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send premium support requests with an attacker-controlled subject line and email address to support allowing them to impersonate the site owner. License information may also be leaked.

References

Affected packages

Git / github.com/rebelcode/wp-rss-aggregator

Affected ranges

Type
GIT
Repo
https://github.com/rebelcode/wp-rss-aggregator
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

4.*
4.19.1
4.19.2
4.19.3
4.20
4.23.3
v4.*
v4.12.1
v4.12.2
v4.12.3
v4.13
v4.13.1
v4.13.2
v4.14
v4.15
v4.15.1
v4.15.2
v4.16
v4.17
v4.17.1
v4.17.10
v4.17.2
v4.17.3
v4.17.4
v4.17.5
v4.17.6
v4.17.7
v4.17.8
v4.17.9
v4.18
v4.18.1
v4.18.2
v4.19
v4.21
v4.21.1
v4.22.1
v4.22.2
v4.22.3
v4.22.4
v4.23
v4.23.1
v4.23.10
v4.23.11
v4.23.2
v4.23.4
v4.23.5
v4.23.6
v4.23.7
v4.23.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-9583.json"