WordPress RSS Aggregator < 4.20 is susceptible to cross-site scripting. The plugin does not sanitize and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to reflected cross-site scripting.
View the template here CVE-2022-0189.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2022-0189