Record summary

CVE-2023-4521 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Import XML and RSS Feeds

Default status: unaffected

CVE List2.1.4 to < 2.1.5affected

Nuclei templates

1
ProjectDiscoveryCRITICALImport XML and RSS Feeds < 2.1.5 - Unauthenticated RCECVSS 9.8

The Import XML and RSS Feeds WordPress plugin before 2.1.5 allows unauthenticated attackers to execute arbitrary commands via a web shell.

Impact

Allows unauthenticated attackers to execute arbitrary code on the target system.

Remediation

Update the Import XML and RSS Feeds WordPress Plugin to the latest version to mitigate the vulnerability.

Authorsprincechaddha
Template tagscvecve2023wordpresswpwpscanunauthrcemooveagencyvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:mooveagency:import_xml_and_rss_feeds:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"import-xml-feed"
FOFA: body="import-xml-feed"

Source: ProjectDiscovery

References

2