plugin

Wp All Export Vulnerabilities

15 known security issues reported for the Wp All Export WordPress plugin. Most recent disclosed Feb 17, 2026.

1 critical 2 high 3 medium 1 low

Running Wp All Export on your site? Check whether your installed version is affected.

Scan your site free

WP All Export <= 1.4.14 - Unauthenticated Sensitive Information Exposure via PHP Type Juggling

low

The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.14 via the export download endpoint. This is due to a PHP type juggling vulnerability in the security token comparison which uses loose comparison (==) instead of strict comparison (===). Thi...

CVSS:
3.7
Affected:
up to 1.4.14
Fixed in:
1.4.15
Disclosed:
Feb 17, 2026

CVE-2026-1582 on NVD →

Export any WordPress data to XML/CSV [wp-all-export] < 1.4.1

unknown

[en] The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserializa...

Affected:
up to 1.4.1
Fixed in:
1.4.1
Disclosed:
Dec 18, 2023

CVE-2023-5886 on NVD →

Export any WordPress data to XML/CSV [wp-all-export] < 1.4.1

unknown

[en] The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server

Affected:
up to 1.4.1
Fixed in:
1.4.1
Disclosed:
Dec 18, 2023

CVE-2023-4724 on NVD →

Export any WordPress data to XML/CSV [wp-all-export] < 1.4.1

unknown

[en] The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged in users perform unwanted actions leading to remote code execution.

Affected:
up to 1.4.1
Fixed in:
1.4.1
Disclosed:
Dec 18, 2023

CVE-2023-5882 on NVD →

Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 - Cross-Site Request Forgery to Remote Code Execution

high

The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to perform unauthorized actions a...

CVSS:
8.8
Affected:
up to 1.4.1
Fixed in:
1.4.1
Disclosed:
Nov 24, 2023

CVE-2023-5882 on NVD →

Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 - Cross-Site Request Forgery to PHAR Deserialization

high

The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to perform unauthorized actions a...

CVSS:
8.8
Affected:
up to 1.4.1
Fixed in:
1.4.1
Disclosed:
Nov 24, 2023

CVE-2023-5886 on NVD →

Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 - Authenticated (Admin+) Remote Code Execution

medium

The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Remote Code Execution in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version via the 'wp_query' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to execute code on the...

CVSS:
6.4
Affected:
up to 1.4.1
Fixed in:
1.4.1
Disclosed:
Nov 24, 2023

CVE-2023-4724 on NVD →

Export any WordPress data to XML/CSV [wp-all-export] < 1.3.5

unknown

[en] The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.

Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
Jun 13, 2022

CVE-2022-1800 on NVD →

Export any WordPress data to XML/CSV <= 1.3.5 - Reflected Cross-Site Scripting

medium

The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.3.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

CVSS:
6.1
Affected:
up to 1.3.5
Fixed in:
1.3.6
Disclosed:
Jun 7, 2022

Export any WordPress data to XML/CSV [wp-all-export] < 1.3.6

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Export any WordPress data to XML/CSV plugin (versions <= 1.3.5). Update the WordPress Export any WordPress data to XML/CSV plugin to the latest available version (at least 1.3.6).

Affected:
up to 1.3.6
Fixed in:
1.3.6
Disclosed:
Jun 7, 2022

Export any WordPress data to XML/CSV [wp-all-export] < 1.3.6

unknown

The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.3.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

Affected:
up to 1.3.6
Fixed in:
1.3.6
Disclosed:
Jun 7, 2022

Export any WordPress data to XML/CSV <= 1.3.4 - Authenticated SQL Injection

critical

The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.

CVSS:
9
Affected:
up to 1.3.4
Fixed in:
1.3.5
Disclosed:
May 20, 2022

CVE-2022-1800 on NVD →

Export any WordPress data to XML/CSV [wp-all-export] < 1.3.1

unknown

[en] The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputting it in Manage Exports settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 1.3.1
Fixed in:
1.3.1
Disclosed:
Nov 8, 2021

CVE-2021-24708 on NVD →

WP All Export <= 1.3.0 - Admin+ Stored Cross-Site Scripting

medium

The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputting it in Manage Exports settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVSS:
4.8
Affected:
up to 1.3.1
Fixed in:
1.3.1
Disclosed:
Oct 6, 2021

CVE-2021-24708 on NVD →

Export any WordPress data to XML/CSV [wp-all-export] < 1.3.6

unknown

The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 1.3.6
Fixed in:
1.3.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database