plugin

Import Xml Feed Vulnerabilities

4 known security issues reported for the Import Xml Feed WordPress plugin. Most recent disclosed Apr 5, 2024.

3 critical 1 high

Running Import Xml Feed on your site? Check whether your installed version is affected.

Scan your site free

Import XML and RSS Feeds <= 2.1.5 - Authenticated (Administrator+) Arbitrary File Upload

critical

The Import XML and RSS Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the moove_set_featured_image() function in all versions up to, and including, 2.1.5. This makes it possible for authenticated attackers, with administrator-level access and above, to upload a...

CVSS:
9.1
Affected:
up to 2.1.5
Fixed in:
2.1.6
Disclosed:
Apr 5, 2024

CVE-2024-31292 on NVD →

Import XML and RSS Feeds <= 2.1.4 - Unauthenticated Remote Code Execution

critical

The Import XML and RSS Feeds for WordPress is vulnerable to remote code execution in versions up to, and including, 2.1.4. This is due to the plugin vendor leaving a malicious file behind when patching CVE-2023-4300. This makes it possible for unauthenticated attackers to access the 169227090864de013cac47b.php file and...

CVSS:
9.8
Affected:
up to 2.1.4
Fixed in:
2.1.5
Disclosed:
Aug 28, 2023

CVE-2023-4521 on NVD →

Import XML and RSS Feeds <= 2.1.3 - Authenticated (Admin+) Arbitrary File Upload

high

The Import XML and RSS Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the moove_save_import_template() function in versions up to, and including, 2.1.3. This makes it possible for authenticated attackers with administrative-level access to upload arbitrary file...

CVSS:
7.2
Affected:
up to 2.1.3
Fixed in:
2.1.4
Disclosed:
Aug 28, 2023

CVE-2023-4300 on NVD →

Import XML and RSS Feeds <= 2.0.2 - Server-Side Request Forgery

critical

The Import XML and RSS Feeds plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.0.2 via the data parameter in a moove_read_xml action.

CVSS:
9.1
Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Apr 13, 2021

CVE-2020-24148 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database