WDS Multisite Aggregate
WDS Multisite Aggregate has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for WDS Multisite Aggregate has a vendor fix available, so running the current release closes it.
WDS Multisite Aggregate is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.7.35.
CVE-2015-10120WDS Multisite Aggregate <= 1.0.0 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
WDS Multisite Aggregate
Author
webdevstudios
Creates a new site where all the most recent posts/pages/etc on a WordPress network may be collected (much like http://wordpress.com/tags/). For performance reasons the number of posts is limited to a user configurable amount, and the blog itself can be made indexable by search engines or not. Based on and forked from WordPress MU Sitewide Tags Pages plugin by Donncha O Caoimh. WPCLI is supported: wp multisite_aggregate –help. Pluginize was launched in 2016 by WebDevStudios to promote, support, and house all of their WordPress products. Pluginize is not only creating new products for WordPress all the time, but also provides ongoing support and development for WordPress community favorites like CPTUI, CMB2, and more. Install Install in your plugins directory in the usual way and network activate the plugin. There is no need to put it in mu-plugins. Login as a site administrator and go to Super Admin->Sitewide Tags. Aggregate site defaults to “Network Posts” but can be anything. This is the blog where your sitewide posts will live. It will be created if it doesn’t exist. Check “Post to main blog” to use your main blog as the aggregate blog. “Max posts” defaults to 5000. Older posts will be deleted if this threshold is broken. Check “Include Pages” to include both posts and pages, handy for making a sitewide search. “Privacy” defaults to public, pages can be indexed by search engines. When “Privacy” is not public, check “Non-Public Blogs” to include blogs not indexed by search engines. Add “Post Meta” custom fields to be copied with posts/pages. “Populate Posts” allows you to fill in posts from an existing blog.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C