Import XML and RSS Feeds < 2.1.5 - Unauthenticated RCE
CVE-2023-4521
Key Information:
- Vendor
Wordpress
- Status
- Vendor
- CVE Published:
- 25 September 2023
Badges
What is CVE-2023-4521?
The Import XML and RSS Feeds WordPress plugin prior to version 2.1.5 is susceptible to a flaw that enables unauthenticated attackers to execute remote code on the affected site. This vulnerability arises from an oversight related to the handling of files generated by a proof-of-concept for an earlier reported issue. Specifically, the failure to delete the generated web shell files during the release of a new version poses a significant security risk. Site administrators using this plugin should apply necessary updates to mitigate potential exploitation.
Affected Version(s)
Import XML and RSS Feeds 2.1.4 < 2.1.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
90% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved