Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mooveagency import xml and rss feeds vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-4521
The Import XML and RSS Feeds WordPress plugin prior to 2.1.5 contains a web shell, allowing unauthenticated malicious users to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vuln...
Mooveagency Import Xml And Rss Feeds
9.1
CVSSv3
CVE-2020-24148
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.
Mooveagency Import Xml And Rss Feeds 2.0.1
1 Github repository
7.2
CVSSv3
CVE-2023-4300
The Import XML and RSS Feeds WordPress plugin prior to 2.1.4 does not filter file extensions for uploaded files, allowing an malicious user to upload a malicious PHP file, leading to Remote Code Execution.
Mooveagency Import Xml And Rss Feeds
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started