WP All Export Pro <= 1.9.1 - Authenticated (ShopManager+) Arbtirary Options Update
medium
The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Shop Manager-level access and a...
- CVSS:
- 6.8
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.2
- Disclosed:
- Feb 7, 2025
CVE-2024-7425 on NVD →
WP All Export Pro <= 1.9.1 - Unauthenticated Remote Code Execution via Custom Export Fields
high
The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.1 via the custom export fields. This is due to the missing input validation and sanitization of user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary PHP cod...
- CVSS:
- 8.3
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.2
- Disclosed:
- Feb 7, 2025
CVE-2024-7419 on NVD →
Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 - Cross-Site Request Forgery to Remote Code Execution
high
The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to perform unauthorized actions a...
- CVSS:
- 8.8
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Nov 24, 2023
CVE-2023-5882 on NVD →
Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 - Cross-Site Request Forgery to PHAR Deserialization
high
The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to perform unauthorized actions a...
- CVSS:
- 8.8
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Nov 24, 2023
CVE-2023-5886 on NVD →
Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 - Authenticated (Admin+) Remote Code Execution
medium
The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Remote Code Execution in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version via the 'wp_query' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to execute code on the...
- CVSS:
- 6.4
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Nov 24, 2023
CVE-2023-4724 on NVD →
WP ALL Export Pro <= 1.7.8 - Authenticated Remote Code Execution
high
The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.7.8. This allows low-level attackers (depending on whether they have been given permission to perform exports) to execute code on the server. While the plugin defaults to allow only administrators to pe...
- CVSS:
- 8.8
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.9
- Disclosed:
- Oct 3, 2022
CVE-2022-3394 on NVD →
WP ALL Export Pro <= 1.7.8 - Authenticated SQL Injection
high
The WP ALL Export Pro plugin for WordPress is vulnerable to SQL Injection via the cc_sql parameter in versions up to, and including, 1.7.8. This allows low-level attackers (depending on whether they have been given permission to perform SQL queries) to to append additional SQL queries into already existing queries tha...
- CVSS:
- 8.8
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.9
- Disclosed:
- Oct 3, 2022
CVE-2022-3395 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database