Export All URLs - Unauthenticated Sensitive Data Exposure vulnerability
mediumUnauthenticated Sensitive Data Exposure vulnerability
- CVSS:
- 5.3
- Affected:
- up to 5.1
- Fixed in:
- 5.1
- Disclosed:
- Apr 2, 2026
plugin
14 known security issues reported for the Export All Urls WordPress plugin. Most recent disclosed Apr 2, 2026.
Running Export All Urls on your site? Check whether your installed version is affected.
Scan your site freeUnauthenticated Sensitive Data Exposure vulnerability
The Export All URLs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 5.1 (exclusive). This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
[en] The Export All URLs WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
The Export All URLs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'starting-point' and 'ending-point' parameters in versions up to, and including, 4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...
[en] Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Atlas Gondal Export All URLs plugin <= 4.1 versions.
[en] The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server
The Export All URLs for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 4.3 due to missing file path and type validation in the ~/extract-all-urls-settings.php file on the 'f' parameter. This makes it possible for authenticated attackers with administrative privileges to deleted a...
[en] Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin <= 4.1 at WordPress.
The Export All URLs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that wi...
The Export All URLs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that wi...
[en] The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting
[en] The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for exampl...
The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example
The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free