Mooveagency develops a small suite of WordPress plugins focused on compliance, content syndication, user tracking, and form validation, addressing niche administrative and data-governance use cases within the WordPress ecosystem. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the recurring exposure centers on web-layer input-handling and authorization weaknesses such as cross-site scripting, missing access controls, and server-side request forgery that are characteristic of plugin-based functionality operating within a shared hosting environment. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mooveagency over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4521CRITICAL The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the fi | Sep 25, 2023 | 9.8 | 59 | NO | YES |
CVE-2020-24148CRITICAL Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action. | Jul 7, 2021 | 9.1 | 47 | NO | YES |
CVE-2021-24286MEDIUM The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Si | May 14, 2021 | 6.1 | 45 | NO | YES |
CVE-2021-24287MEDIUM The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before out | May 14, 2021 | 6.1 | 43 | NO | YES |
CVE-2021-24247MEDIUM The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any regist | May 6, 2021 | 5.4 | 29 | NO | YES |
CVE-2023-4300HIGH The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remot | Sep 25, 2023 | 7.2 | 23 | NO | NO |
CVE-2024-31292HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affects Import XML and RSS Feeds: from n/a through 2.1.5. | Apr 7, 2024 | 7.2 | 22 | NO | NO |
CVE-2023-4013MEDIUM The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 4.12.5 does not have proper CSRF checks when managing its license, which could allow attackers to m | Aug 30, 2023 | 6.5 | 21 | NO | NO |
CVE-2025-1620MEDIUM The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored | Mar 16, 2025 | 4.8 | 19 | NO | NO |
CVE-2025-2205MEDIUM The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i | Mar 12, 2025 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mooveagency.
Media articles that mention a CVE ID that affects a product developed by Mooveagency — matched by CVE ID, not by vendor name.