CVE-2023-4521
Import XML and RSS Feeds < 2.1.5 - Unauthenticated RCE
Vexday Risk Score
60Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.8EPSS 39.6%KEV nãoPoC públicaPatch —
Lifecycle
25 Sep 2023Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · Import XML and RSS Feedspublic PoCs found — 1
cve_referencewpscan.com/vulnerability/de2cdb38-3a9f-448e-b564-a798d1e93481unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →