Back to search
CVE-2023-4300
Published: Sep 25, 2023
Modified: Apr 23, 2025
PUBLISHED
Description
The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remote Code Execution.
| Vendor | Product | Versions |
|---|---|---|
Unknown | Import XML and RSS Feeds | affected 0 - < 2.1.4 |
References
https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42
exploit
vdb-entry
technical-description
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now