Description
The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 23 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-23T16:15:47.593Z
Reserved: 2023-08-24T15:33:51.246Z
Link: CVE-2023-4521
Updated: 2024-08-02T07:31:06.087Z
Status : Modified
Published: 2023-09-25T16:15:15.297
Modified: 2025-04-23T17:16:45.140
Link: CVE-2023-4521
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.