CVE-2023-4521: Import XML and RSS Feeds < 2.1.5 - Unauthenticated RCE
The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Import XML and RSS Feeds WordPress plugin?
The vulnerability ID for the Import XML and RSS Feeds WordPress plugin is CVE-2023-4521.
What is the severity level of CVE-2023-4521 vulnerability?
The severity level of CVE-2023-4521 vulnerability is critical with a severity value of 9.8.
What is the affected software for CVE-2023-4521 vulnerability?
The affected software for CVE-2023-4521 vulnerability is Mooveagency Import Xml And Rss Feeds WordPress plugin version up to 2.1.5.
What is the description of CVE-2023-4521 vulnerability?
The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform remote code execution (RCE).
How can I fix the CVE-2023-4521 vulnerability in Import XML and RSS Feeds WordPress plugin?
To fix the CVE-2023-4521 vulnerability, update the Mooveagency Import Xml And Rss Feeds WordPress plugin to version 2.1.5 or later.