plugin

Wp All Export Pro Vulnerabilities

7 known security issues reported for the Wp All Export Pro WordPress plugin. Most recent disclosed Feb 7, 2025.

5 high 2 medium

Running Wp All Export Pro on your site? Check whether your installed version is affected.

Scan your site free

WP All Export Pro <= 1.9.1 - Authenticated (ShopManager+) Arbtirary Options Update

medium

The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated attackers, with Shop Manager-level access and a...

CVSS:
6.8
Affected:
up to 1.9.1
Fixed in:
1.9.2
Disclosed:
Feb 7, 2025

CVE-2024-7425 on NVD →

WP All Export Pro <= 1.9.1 - Unauthenticated Remote Code Execution via Custom Export Fields

high

The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.1 via the custom export fields. This is due to the missing input validation and sanitization of user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary PHP cod...

CVSS:
8.3
Affected:
up to 1.9.1
Fixed in:
1.9.2
Disclosed:
Feb 7, 2025

CVE-2024-7419 on NVD →

Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 - Cross-Site Request Forgery to Remote Code Execution

high

The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to perform unauthorized actions a...

CVSS:
8.8
Affected:
up to 1.8.6
Fixed in:
1.8.6
Disclosed:
Nov 24, 2023

CVE-2023-5882 on NVD →

Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 - Cross-Site Request Forgery to PHAR Deserialization

high

The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to perform unauthorized actions a...

CVSS:
8.8
Affected:
up to 1.8.6
Fixed in:
1.8.6
Disclosed:
Nov 24, 2023

CVE-2023-5886 on NVD →

Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 - Authenticated (Admin+) Remote Code Execution

medium

The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Remote Code Execution in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version via the 'wp_query' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to execute code on the...

CVSS:
6.4
Affected:
up to 1.8.6
Fixed in:
1.8.6
Disclosed:
Nov 24, 2023

CVE-2023-4724 on NVD →

WP ALL Export Pro <= 1.7.8 - Authenticated Remote Code Execution

high

The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.7.8. This allows low-level attackers (depending on whether they have been given permission to perform exports) to execute code on the server. While the plugin defaults to allow only administrators to pe...

CVSS:
8.8
Affected:
up to 1.7.8
Fixed in:
1.7.9
Disclosed:
Oct 3, 2022

CVE-2022-3394 on NVD →

WP ALL Export Pro <= 1.7.8 - Authenticated SQL Injection

high

The WP ALL Export Pro plugin for WordPress is vulnerable to SQL Injection via the cc_sql parameter in versions up to, and including, 1.7.8. This allows low-level attackers (depending on whether they have been given permission to perform SQL queries) to to append additional SQL queries into already existing queries tha...

CVSS:
8.8
Affected:
up to 1.7.8
Fixed in:
1.7.9
Disclosed:
Oct 3, 2022

CVE-2022-3395 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database