Export All Posts, Products, Orders, Refunds & Users [wp-ultimate-exporter] < 2.20
unknown
[en] The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.19. This is due to missing or incorrect nonce validation on the `parseData` function. This makes it possible for unauthenticated attackers to export sensi...
- Affected:
- up to 2.20
- Fixed in:
- 2.20
- Disclosed:
- Dec 2, 2025
CVE-2025-13606 on NVD →
Export All Posts, Products, Orders, Refunds & Users <= 2.19 - Cross-Site Request Forgery to Sensitive Information Exposure
medium
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.19. This is due to missing or incorrect nonce validation on the `parseData` function. This makes it possible for unauthenticated attackers to export sensitive...
- CVSS:
- 6.5
- Affected:
- up to 2.19
- Fixed in:
- 2.20
- Disclosed:
- Dec 1, 2025
CVE-2025-13606 on NVD →
Export All Posts, Products, Orders, Refunds & Users <= 2.13 - Unauthenticated PHP Object Injection
critical
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of untrusted input in the 'returnMetaValueAsCustomerInput' function. This makes it possible for unauthenticated attackers to inject a PHP Obje...
- CVSS:
- 9.8
- Affected:
- up to 2.13
- Fixed in:
- 2.14
- Disclosed:
- Mar 26, 2025
CVE-2025-2332 on NVD →
Export All Posts, Products, Orders, Refunds & Users [wp-ultimate-exporter] < 2.10
unknown
[en] The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/upl...
- Affected:
- up to 2.10
- Fixed in:
- 2.10
- Disclosed:
- Feb 12, 2025
CVE-2024-12315 on NVD →
Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directory
high
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/...
- CVSS:
- 7.5
- Affected:
- up to 2.9.3
- Fixed in:
- 2.10
- Disclosed:
- Feb 11, 2025
CVE-2024-12315 on NVD →
WP Ultimate Exporter <= 2.9 - Authenticated (Admin+) Arbitrary File Read
medium
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain...
- CVSS:
- 4.9
- Affected:
- up to 2.9
- Fixed in:
- 2.9.1
- Disclosed:
- Jan 24, 2025
CVE-2025-24611 on NVD →
Export All Posts, Products, Orders, Refunds & Users [wp-ultimate-exporter] < 2.9.1
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Smackcoders WP Ultimate Exporter allows Absolute Path Traversal. This issue affects WP Ultimate Exporter: from n/a through 2.9.
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.1
- Disclosed:
- Jan 24, 2025
CVE-2025-24611 on NVD →
Export All Posts, Products, Orders, Refunds & Users [wp-ultimate-exporter] < 2.9.2
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders WP Ultimate Exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through 2.9.1.
- Affected:
- up to 2.9.2
- Fixed in:
- 2.9.2
- Disclosed:
- Jan 7, 2025
CVE-2024-56278 on NVD →
WP Ultimate Exporter <= 2.9.1 - Authenticated (Admin+) Remote Code Execution
medium
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
- CVSS:
- 4.1
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.2
- Disclosed:
- Jan 3, 2025
CVE-2024-56278 on NVD →
Export All Posts, Products, Orders, Refunds & Users [wp-ultimate-exporter] < 2.4.2
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.2
- Disclosed:
- Dec 21, 2023
CVE-2023-2487 on NVD →
Export All Posts, Products, Orders, Refunds & Users [wp-ultimate-exporter] <= 2.4.1 (unfixed)
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.
- Affected:
- up to 2.4.1
- Fix:
- No patched version reported
- Disclosed:
- Nov 30, 2023
CVE-2023-45066 on NVD →
WP Ultimate Exporter <= 2.4.1 - Unauthenticated Information Disclosure
medium
The WP Ultimate Exporter plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.4.1 due to insufficient protection on the directory in which exported files are stored in. This can allow unauthenticated attackers to extract sensitive data from accessible log files which...
- CVSS:
- 5.3
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.2
- Disclosed:
- Oct 3, 2023
CVE-2023-2487 on NVD →
Export All Posts, Products, Orders, Refunds & Users [wp-ultimate-exporter] < 1.2
unknown
[en] The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Sep 20, 2019
CVE-2016-11000 on NVD →
Export All Posts, Products, Orders, Refunds & Users [wp-ultimate-exporter] < 1.4.2
unknown
[en] The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.2
- Disclosed:
- Aug 14, 2019
CVE-2018-20968 on NVD →
Export WordPress Data with Advanced Filters <= 1.4.1 - Cross-Site Request Forgery
high
The Export WordPress Data with Advanced Filters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1. This is due to missing or incorrect nonce validation on the export_module() function. This makes it possible for unauthenticated attackers to export module data via a...
- CVSS:
- 8.8
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.2
- Disclosed:
- Dec 19, 2018
CVE-2018-20968 on NVD →
Export WordPress Data with Advanced Filters < 1.2 - SQL Injection
critical
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.1
- Fixed in:
- 1.2
- Disclosed:
- Feb 25, 2016
CVE-2016-11000 on NVD →
Export All Posts, Products, Orders, Refunds & Users [wp-ultimate-exporter] < 1.2
unknown
This plugin is prone to an SQL injection vulnerability. It allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update the plugin.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Feb 25, 2016
WP Ultimate Exporter < 1.1 - Reflected Cross-Site Scripting
medium
The WP Ultimate Exporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘export_name’ and 'export_post_type_name' parameters in versions before 1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...
- CVSS:
- 6.1
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Feb 24, 2016
Export All Posts, Products, Orders, Refunds & Users [wp-ultimate-exporter] < 1.1
unknown
The WP Ultimate Exporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘export_name’ and 'export_post_type_name' parameters in versions before 1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Feb 24, 2016
Export All Posts, Products, Orders, Refunds & Users [wp-ultimate-exporter] < 1.1
unknown
This plugin is prone to a cross site scripting vulnerability, because "export_name" and "export_post_type_name" parameters are not sanitized.
Update the plugin.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Feb 24, 2016
Export All Posts, Products, Orders, Refunds & Users [wp-ultimate-exporter] < 1.1
unknown
The Export WordPress Data with Advanced Filters WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
Export All Posts, Products, Orders, Refunds & Users [wp-ultimate-exporter] < 2.14
unknown
- Affected:
- up to 2.14
- Fixed in:
- 2.14
CVE-2025-2332 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database