Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mooveagency

First CVE: May 6, 2021Active for: 5 yearsTotal CVEs: 18
30.3
VTI Score
Low

Mooveagency develops a small suite of WordPress plugins focused on compliance, content syndication, user tracking, and form validation, addressing niche administrative and data-governance use cases within the WordPress ecosystem. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the recurring exposure centers on web-layer input-handling and authorization weaknesses such as cross-site scripting, missing access controls, and server-side request forgery that are characteristic of plugin-based functionality operating within a shared hosting environment. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mooveagency over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 6, 2021
5 years ago
Most Recent CVE
May 15, 2025
435 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-4521CRITICAL
The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the fi
Sep 25, 20239.859NOYES
CVE-2020-24148CRITICAL
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.
Jul 7, 20219.147NOYES
CVE-2021-24286MEDIUM
The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Si
May 14, 20216.145NOYES
CVE-2021-24287MEDIUM
The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before out
May 14, 20216.143NOYES
CVE-2021-24247MEDIUM
The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any regist
May 6, 20215.429NOYES
CVE-2023-4300HIGH
The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remot
Sep 25, 20237.223NONO
CVE-2024-31292HIGH
Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affects Import XML and RSS Feeds: from n/a through 2.1.5.
Apr 7, 20247.222NONO
CVE-2023-4013MEDIUM
The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 4.12.5 does not have proper CSRF checks when managing its license, which could allow attackers to m
Aug 30, 20236.521NONO
CVE-2025-1620MEDIUM
The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored
Mar 16, 20254.819NONO
CVE-2025-2205MEDIUM
The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i
Mar 12, 20254.818NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
17%
61%
11%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (33.3%)
Unknown0 (0.0%)
Required12 (66.7%)
Privileges Required
Low2 (11.1%)
High9 (50.0%)
None7 (38.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
22.2% of CVEs· 97th percentile
ExploitDB
3 CVEs
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mooveagency.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mooveagency — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mooveagency's Products

View all 4 CNAs →

Top CWEs