What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affects Import XML and RSS Feeds: from n/a through 2.1.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affects Import XML and RSS Feeds: from n/a through 2.1.5.
Explanation of Vulnerability in Simple Terms
The Import XML and RSS Feeds plugin for WordPress contains an unrestricted file upload vulnerability in versions up to 2.1.5. An authenticated administrator can upload arbitrary files to the site, potentially including PHP scripts or other executable code. This allows an attacker with admin access to gain full control of the site's file system and execute malicious code.
What an attacker can do
Upload arbitrary files, including executable code, to the site's server.
Potential impact on your site
A compromised admin account can be used to upload malware, backdoors, or web shells, leading to full site compromise.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities