While looking through my security RSS feeds I found out that there is a XSS in older versions of the RSS plugin. It seems to have been fixed in the latest version if s9y.
Note that you only need to upgrade when using the Remote RSS sidebar plugin. Not soo many blogs even have that enabled.
Also be sure to subscribe to blog.s9y.org, it contains new version announcements.
Regards,
Garvin
# Garvin Hicking (s9y Developer)
# Did I help you? Consider making me happy: http://wishes.garv.in/
# or use my PayPal account "paypal {at} supergarv (dot) de"
# My "other" hobby: http://flickr.garv.in/
Ahh, it was just the RSS inclusion sidebar. I was thinking it was the RSS sidebar for changing the format of your RSS feed. The severity just went from a 10/10 in my mind to a 2/10.