CVE-2020-24148: Mooveagency Import XML And Rss Feeds
Critical severity, CVSS 9.1. EPSS: 14.7% chance of exploitation in the next 30 days.
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.
Affected products
- Mooveagency Import XML And Rss Feeds: version 2.0.1 only
Published 2021-07-07. Last modified 2026-06-17.