The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-23T16:15:47.593Z
Reserved: 2023-08-24T15:33:51.246Z
Link: CVE-2023-4521
Updated: 2024-08-02T07:31:06.087Z
Status : Modified
Published: 2023-09-25T16:15:15.297
Modified: 2025-04-23T17:16:45.140
Link: CVE-2023-4521
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.