CVE-2023-4521
Import XML and RSS Feeds < 2.1.5 - Unauthenticated RCE
Record summary
CVE-2023-4521 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Import XML and RSS FeedsDefault status: unaffected | CVE List | 2.1.4 to < 2.1.5 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALImport XML and RSS Feeds < 2.1.5 - Unauthenticated RCECVSS 9.8
The Import XML and RSS Feeds WordPress plugin before 2.1.5 allows unauthenticated attackers to execute arbitrary commands via a web shell.
Impact
Allows unauthenticated attackers to execute arbitrary code on the target system.
Remediation
Update the Import XML and RSS Feeds WordPress Plugin to the latest version to mitigate the vulnerability.
Source: ProjectDiscovery