RULE(RULE ID:338427)

Rule General Information
Release Date: 2024-09-18
Rule Name: WordPress Plugin Cross-RSS Arbitrary File Reading Vulnerability (CVE-2014-4941)
Severity:
CVE ID:
Rule Protection Details
Description: Absolute path traversal vulnerability in Cross-RSS (wp-cross-rss) plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a full pathname in the rss parameter to proxy.php.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: http://codevigilant.com/disclosure/wp-plugin-cross-rss-local-file-inclusion/
Solutions
Refer to the announcement or patch by the vendor: http://www.wordpress.org/plugins/cross-rss