CVE-2020-24148: SSRF
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moovereadxml action.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24148?
CVE-2020-24148 is a vulnerability known as Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress.
How severe is CVE-2020-24148?
CVE-2020-24148 is classified as a critical vulnerability with a severity score of 9.1 out of 10.
What is the affected software for CVE-2020-24148?
The affected software is the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress (Mooveagency Import Xml And Rss Feeds).
How can CVE-2020-24148 be exploited?
CVE-2020-24148 can be exploited via the data parameter in a moove_read_xml action.
Where can I find more information about CVE-2020-24148?
More information about CVE-2020-24148 can be found at the following references: [GitHub](https://github.com/secwx/research/blob/main/cve/CVE-2020-24148.md) [WordPress Plugin](https://wordpress.org/plugins/import-xml-feed/#developers).