WP All Export <= 1.4.14 - Unauthenticated Sensitive Information Exposure via PHP Type Juggling
low
The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.14 via the export download endpoint. This is due to a PHP type juggling vulnerability in the security token comparison which uses loose comparison (==) instead of strict comparison (===). Thi...
- CVSS:
- 3.7
- Affected:
- up to 1.4.14
- Fixed in:
- 1.4.15
- Disclosed:
- Feb 17, 2026
CVE-2026-1582 on NVD →
Export any WordPress data to XML/CSV [wp-all-export] < 1.4.1
unknown
[en] The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserializa...
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
- Disclosed:
- Dec 18, 2023
CVE-2023-5886 on NVD →
Export any WordPress data to XML/CSV [wp-all-export] < 1.4.1
unknown
[en] The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
- Disclosed:
- Dec 18, 2023
CVE-2023-4724 on NVD →
Export any WordPress data to XML/CSV [wp-all-export] < 1.4.1
unknown
[en] The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged in users perform unwanted actions leading to remote code execution.
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
- Disclosed:
- Dec 18, 2023
CVE-2023-5882 on NVD →
Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 - Cross-Site Request Forgery to Remote Code Execution
high
The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to perform unauthorized actions a...
- CVSS:
- 8.8
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
- Disclosed:
- Nov 24, 2023
CVE-2023-5882 on NVD →
Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 - Cross-Site Request Forgery to PHAR Deserialization
high
The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to perform unauthorized actions a...
- CVSS:
- 8.8
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
- Disclosed:
- Nov 24, 2023
CVE-2023-5886 on NVD →
Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 - Authenticated (Admin+) Remote Code Execution
medium
The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Remote Code Execution in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version via the 'wp_query' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to execute code on the...
- CVSS:
- 6.4
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
- Disclosed:
- Nov 24, 2023
CVE-2023-4724 on NVD →
Export any WordPress data to XML/CSV [wp-all-export] < 1.3.5
unknown
[en] The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Jun 13, 2022
CVE-2022-1800 on NVD →
Export any WordPress data to XML/CSV <= 1.3.5 - Reflected Cross-Site Scripting
medium
The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.3.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.1
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.6
- Disclosed:
- Jun 7, 2022
Export any WordPress data to XML/CSV [wp-all-export] < 1.3.6
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Export any WordPress data to XML/CSV plugin (versions <= 1.3.5).
Update the WordPress Export any WordPress data to XML/CSV plugin to the latest available version (at least 1.3.6).
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Jun 7, 2022
Export any WordPress data to XML/CSV [wp-all-export] < 1.3.6
unknown
The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.3.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Jun 7, 2022
Export any WordPress data to XML/CSV <= 1.3.4 - Authenticated SQL Injection
critical
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.
- CVSS:
- 9
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.5
- Disclosed:
- May 20, 2022
CVE-2022-1800 on NVD →
Export any WordPress data to XML/CSV [wp-all-export] < 1.3.1
unknown
[en] The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputting it in Manage Exports settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- Nov 8, 2021
CVE-2021-24708 on NVD →
WP All Export <= 1.3.0 - Admin+ Stored Cross-Site Scripting
medium
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputting it in Manage Exports settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 4.8
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- Oct 6, 2021
CVE-2021-24708 on NVD →
Export any WordPress data to XML/CSV [wp-all-export] < 1.3.6
unknown
The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database