Custom Simple Rss
Custom Simple Rss has one disclosed vulnerability in the WordSec catalog, all reported in 2019; it is fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 6.5 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Custom Simple Rss has a vendor fix available, so running the current release closes it.
All of these findings were reported by Mehdi Esmaeilpour. Custom Simple Rss is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.7.17.
CVE-2019-14327Custom Simple RSS < 2.0.7 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Custom Simple Rss
Author
danikoo
NEW: 1. added – option to choose multiple post types, example: ?call_custom_simple_rss=1&csrp_post_type=page,post 2. added – option to choose multiple post status, example: ?call_custom_simple_rss=1&csrp_post_status=publish,draft 3. added – better documentation (tutorial). A plugin to create a your own Custom Simple RSS Feed according to parameters you choose! *** the best solution for using MailChimp RSS campaigns *** in simple words: Ever wanted an rss feed for just a specific Author and specific Category? Or Even an rss feed for a specific Custom Field ??? Well… now you got it ! The plugin does not alter your default wordpress feeds – it enables you to display feeds on the fly via specific url with pre defined url query parameters. for example: display only 5 items from specific category order by name descending: www.yordomain.com/?call_custom_simple_rss=1&csrp_posts_per_page=5 &csrp_orderby=name&csrp_order=DESC&csrp_cat=4 Filter items by: category id post type post status tag range of dates and even meta keys and values! NEW! filter by custom taxonomy Order by: name date author ID etc More Features: number of items to return pagination show post thumbnail or not? set post thumbnails size to display? show post custom fields (espically usefull if your using your rss as an affliate feed) filter by date published or modified
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C