CVE-2020-24148: Mooveagency Import XML And Rss Feeds

Critical severity, CVSS 9.1. EPSS: 14.7% chance of exploitation in the next 30 days.

Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.

Affected products

  • Mooveagency Import XML And Rss Feeds: version 2.0.1 only

Published 2021-07-07. Last modified 2026-06-17.