CVE-2024-31292: WordPress Import XML and RSS Feeds plugin <= 2.1.5 - Arbitrary File Upload vulnerability
Published Apr 7, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affects Import XML and RSS Feeds: from n/a through 2.1.5.
Affected Software
1 affected component
Moove Agency Import XML and RSS Feeds<=2.1.5
Remediation
Information
Update to 2.1.6 or a higher version.
Event History
Apr 7, 2024
CVE Published
via MITRE·05:29 PM
Data Sourced
via MITRE·05:29 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31292?
CVE-2024-31292 is considered a high severity vulnerability due to the potential for arbitrary file uploads.
2
How do I fix CVE-2024-31292?
Fix CVE-2024-31292 by updating the Moove Agency Import XML and RSS Feeds plugin to the latest version.
3
Which versions are affected by CVE-2024-31292?
CVE-2024-31292 affects versions of Moove Agency Import XML and RSS Feeds up to and including 2.1.5.
4
What type of vulnerability is CVE-2024-31292?
CVE-2024-31292 is classified as an Unrestricted Upload of File with Dangerous Type vulnerability.
5
What platforms does CVE-2024-31292 impact?
CVE-2024-31292 impacts both Moove Agency Import XML and RSS Feeds and WordPress Import XML and RSS Feeds plugins running versions up to 2.1.5.