Vulnerabilities > Mooveagency > Import XML AND RSS Feeds > 2.0.3

DATE CVE VULNERABILITY TITLE RISK
2023-09-25 CVE-2023-4300 Unspecified vulnerability in Mooveagency Import XML and RSS Feeds
The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remote Code Execution.
network
low complexity
mooveagency
7.2
2023-09-25 CVE-2023-4521 Unspecified vulnerability in Mooveagency Import XML and RSS Feeds
The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE.
network
low complexity
mooveagency
critical
9.8