plugin

Export All Urls Vulnerabilities

14 known security issues reported for the Export All Urls WordPress plugin. Most recent disclosed Apr 2, 2026.

1 high 7 medium

Running Export All Urls on your site? Check whether your installed version is affected.

Scan your site free

Export All URLs - Unauthenticated Sensitive Data Exposure vulnerability

medium

Unauthenticated Sensitive Data Exposure vulnerability

CVSS:
5.3
Affected:
up to 5.1
Fixed in:
5.1
Disclosed:
Apr 2, 2026

Export All URLs < 5.1 - Unauthenticated Information Exposure

high

The Export All URLs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 5.1 (exclusive). This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
7.5
Affected:
up to 5.1
Fixed in:
5.1
Disclosed:
Apr 2, 2026

CVE-2026-2696 on NVD →

Export All URLs [export-all-urls] < 4.6

unknown

[en] The Export All URLs WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 4.6
Fixed in:
4.6
Disclosed:
Jul 10, 2023

CVE-2023-3118 on NVD →

Export All URLs <= 4.5 - Reflected Cross-Site Scripting

medium

The Export All URLs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'starting-point' and 'ending-point' parameters in versions up to, and including, 4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

CVSS:
6.1
Affected:
up to 4.5
Fixed in:
4.6
Disclosed:
Jun 19, 2023

CVE-2023-3118 on NVD →

Export All URLs [export-all-urls] < 4.2

unknown

[en] Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Atlas Gondal Export All URLs plugin <= 4.1 versions.

Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
May 10, 2023

CVE-2022-27856 on NVD →

Export All URLs [export-all-urls] < 4.4

unknown

[en] The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Aug 29, 2022

CVE-2022-2638 on NVD →

Export All URLs <= 4.3 - Arbitrary File Deletion

medium

The Export All URLs for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 4.3 due to missing file path and type validation in the ~/extract-all-urls-settings.php file on the 'f' parameter. This makes it possible for authenticated attackers with administrative privileges to deleted a...

CVSS:
6.5
Affected:
up to 4.3
Fixed in:
4.4
Disclosed:
Aug 8, 2022

CVE-2022-2638 on NVD →

Export All URLs [export-all-urls] < 4.2

unknown

[en] Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin <= 4.1 at WordPress.

Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Jun 15, 2022

CVE-2022-29452 on NVD →

Export All URLs <= 4.1 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Export All URLs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
6.4
Affected:
up to 4.1
Fixed in:
4.2
Disclosed:
May 27, 2022

CVE-2022-27856 on NVD →

Export All URLs <= 4.1 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Export All URLs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
4.4
Affected:
up to 4.1
Fixed in:
4.2
Disclosed:
May 27, 2022

CVE-2022-29452 on NVD →

Export All URLs [export-all-urls] < 4.2

unknown

[en] The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting

Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Apr 11, 2022

CVE-2022-0892 on NVD →

Export All URLs [export-all-urls] < 4.3

unknown

[en] The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for exampl...

Affected:
up to 4.3
Fixed in:
4.3
Disclosed:
Apr 11, 2022

CVE-2022-0914 on NVD →

Export All URLs <= 4.2 - Cross-Site Request Forgery to Sensitive Data Export

medium

The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example

CVSS:
6.5
Affected:
up to 4.3
Fixed in:
4.3
Disclosed:
Mar 21, 2022

CVE-2022-0914 on NVD →

Export All URLs <= 4.1 - Reflected Cross-Site Scripting

medium

The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Mar 21, 2022

CVE-2022-0892 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database