Vulnerabilities > CVE-2023-4300 - Unspecified vulnerability in Mooveagency Import XML and RSS Feeds

047910
CVSS 7.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
mooveagency

Summary

The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remote Code Execution.

Vulnerable Configurations

Part Description Count
Application
Mooveagency
38