Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Import XML and RSS Feeds | 2.1.4 ~ 2.1.5 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The Import XML and RSS Feeds WordPress plugin before 2.1.5 allows unauthenticated attackers to execute arbitrary commands via a web shell. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4521.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-4490 | WP Job Portal < 2.0.6 - Unauthenticated SQLi | |
| CVE-2023-4300 | Import XML and RSS Feeds < 2.1.4 - Admin+ Arbitrary File Upload | |
| CVE-2023-3226 | Popup Builder < 4.2.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2023-4281 | Activity Log < 2.8.8 - IP Spoofing | |
| CVE-2023-4238 | Prevent files / folders access < 2.5.2 - Admin+ Arbitrary File Upload | |
| CVE-2023-4631 | DoLogin Security < 3.7 - IP Spoofing | |
| CVE-2023-4502 | Translate WordPress with GTranslate < 3.0.4 - Admin+ Stored XSS | |
| CVE-2023-4148 | Ditty < 3.1.25 - Reflected XSS | |
| CVE-2023-4549 | DoLogin Security < 3.7 - Unauthenticated Stored Cross-Site Scripting | |
| CVE-2023-3664 | FileOrganizer <= 1.0.2 - Admin+ Arbitrary File Access | |
| CVE-2023-3547 | All in One B2B for WooCommerce <= 1.0.3 - Multiple CSRF | |
| CVE-2023-4476 | Locatoraid Store Locator < 3.9.24 - Reflected XSS |
No comments yet