Cross-Site Request Forgery in RSS Digest by Sam Charrington
CVE-2025-53331
7.1HIGH
What is CVE-2025-53331?
A Cross-Site Request Forgery (CSRF) vulnerability in the RSS Digest plugin by Sam Charrington allows an attacker to execute stored cross-site scripting (XSS) attacks. This weakness potentially enables malicious actors to execute harmful scripts in the context of a user's session when interacting with the compromised plugin. The vulnerability affects all versions from n/a to 1.5, posing serious security risks for users of this plugin.
Affected Version(s)
RSS Digest <= 1.5