← WordPress Vulnerabilities
WordPress security by component

Import XML and RSS Feeds

Import XML and RSS Feeds is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Apr 07, 2024; the highest CVE/CNA score is 9.1.

Plugin slug: import-xml-feed

CVE-2024-31292: Import XML and RSS Feeds: Dangerous file upload

Import XML and RSS Feeds is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.

PublishedApr 07, 2024
Safe version guidanceSee mitigation notes
Safe version
Apr 07, 2024 CVE-2024-31292
Import XML and RSS Feeds: Dangerous file upload
Import XML and RSS Feeds is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE7.2
NVDPending
Jul 07, 2021 CVE-2020-24148
Import Xml Feed: Server-side request forgery
Import Xml Feed is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE9.1
NVD9.1