Unauthenticated Remote Code Execution (RCE) via Web Shell in Import XML and RSS Feeds WordPress Plugin

Unauthenticated Remote Code Execution (RCE) via Web Shell in Import XML and RSS Feeds WordPress Plugin

CVE-2023-4521 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.

Learn more about our Wordpress Pen Testing.