The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remote Code Execution.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 24 Apr 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-23T16:16:07.209Z
Reserved: 2023-08-10T20:23:07.259Z
Link: CVE-2023-4300
Updated: 2024-08-02T07:24:04.574Z
Status : Modified
Published: 2023-09-25T16:15:15.000
Modified: 2025-04-23T17:16:43.500
Link: CVE-2023-4300
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.