plugin

Wp Ultimate Exporter Vulnerabilities

22 known security issues reported for the Wp Ultimate Exporter WordPress plugin. Most recent disclosed Dec 2, 2025.

2 critical 2 high 5 medium

Running Wp Ultimate Exporter on your site? Check whether your installed version is affected.

Scan your site free

Export All Posts, Products, Orders, Refunds &amp; Users [wp-ultimate-exporter] < 2.20

unknown

[en] The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.19. This is due to missing or incorrect nonce validation on the `parseData` function. This makes it possible for unauthenticated attackers to export sensi...

Affected:
up to 2.20
Fixed in:
2.20
Disclosed:
Dec 2, 2025

CVE-2025-13606 on NVD →

Export All Posts, Products, Orders, Refunds & Users <= 2.19 - Cross-Site Request Forgery to Sensitive Information Exposure

medium

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.19. This is due to missing or incorrect nonce validation on the `parseData` function. This makes it possible for unauthenticated attackers to export sensitive...

CVSS:
6.5
Affected:
up to 2.19
Fixed in:
2.20
Disclosed:
Dec 1, 2025

CVE-2025-13606 on NVD →

Export All Posts, Products, Orders, Refunds & Users <= 2.13 - Unauthenticated PHP Object Injection

critical

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of untrusted input in the 'returnMetaValueAsCustomerInput' function. This makes it possible for unauthenticated attackers to inject a PHP Obje...

CVSS:
9.8
Affected:
up to 2.13
Fixed in:
2.14
Disclosed:
Mar 26, 2025

CVE-2025-2332 on NVD →

Export All Posts, Products, Orders, Refunds &amp; Users [wp-ultimate-exporter] < 2.10

unknown

[en] The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/upl...

Affected:
up to 2.10
Fixed in:
2.10
Disclosed:
Feb 12, 2025

CVE-2024-12315 on NVD →

Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directory

high

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/...

CVSS:
7.5
Affected:
up to 2.9.3
Fixed in:
2.10
Disclosed:
Feb 11, 2025

CVE-2024-12315 on NVD →

WP Ultimate Exporter <= 2.9 - Authenticated (Admin+) Arbitrary File Read

medium

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain...

CVSS:
4.9
Affected:
up to 2.9
Fixed in:
2.9.1
Disclosed:
Jan 24, 2025

CVE-2025-24611 on NVD →

Export All Posts, Products, Orders, Refunds &amp; Users [wp-ultimate-exporter] < 2.9.1

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Smackcoders WP Ultimate Exporter allows Absolute Path Traversal. This issue affects WP Ultimate Exporter: from n/a through 2.9.

Affected:
up to 2.9.1
Fixed in:
2.9.1
Disclosed:
Jan 24, 2025

CVE-2025-24611 on NVD →

Export All Posts, Products, Orders, Refunds &amp; Users [wp-ultimate-exporter] < 2.9.2

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders WP Ultimate Exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through 2.9.1.

Affected:
up to 2.9.2
Fixed in:
2.9.2
Disclosed:
Jan 7, 2025

CVE-2024-56278 on NVD →

WP Ultimate Exporter <= 2.9.1 - Authenticated (Admin+) Remote Code Execution

medium

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

CVSS:
4.1
Affected:
up to 2.9.1
Fixed in:
2.9.2
Disclosed:
Jan 3, 2025

CVE-2024-56278 on NVD →

Export All Posts, Products, Orders, Refunds &amp; Users [wp-ultimate-exporter] < 2.4.2

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.

Affected:
up to 2.4.2
Fixed in:
2.4.2
Disclosed:
Dec 21, 2023

CVE-2023-2487 on NVD →

Export All Posts, Products, Orders, Refunds &amp; Users [wp-ultimate-exporter] <= 2.4.1 (unfixed)

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.

Affected:
up to 2.4.1
Fix:
No patched version reported
Disclosed:
Nov 30, 2023

CVE-2023-45066 on NVD →

WP Ultimate Exporter <= 2.4.1 - Unauthenticated Information Disclosure

medium

The WP Ultimate Exporter plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.4.1 due to insufficient protection on the directory in which exported files are stored in. This can allow unauthenticated attackers to extract sensitive data from accessible log files which...

CVSS:
5.3
Affected:
up to 2.4.1
Fixed in:
2.4.2
Disclosed:
Oct 3, 2023

CVE-2023-2487 on NVD →

Export All Posts, Products, Orders, Refunds &amp; Users [wp-ultimate-exporter] < 1.2

unknown

[en] The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Sep 20, 2019

CVE-2016-11000 on NVD →

Export All Posts, Products, Orders, Refunds &amp; Users [wp-ultimate-exporter] < 1.4.2

unknown

[en] The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.

Affected:
up to 1.4.2
Fixed in:
1.4.2
Disclosed:
Aug 14, 2019

CVE-2018-20968 on NVD →

Export WordPress Data with Advanced Filters <= 1.4.1 - Cross-Site Request Forgery

high

The Export WordPress Data with Advanced Filters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1. This is due to missing or incorrect nonce validation on the export_module() function. This makes it possible for unauthenticated attackers to export module data via a...

CVSS:
8.8
Affected:
up to 1.4.2
Fixed in:
1.4.2
Disclosed:
Dec 19, 2018

CVE-2018-20968 on NVD →

Export WordPress Data with Advanced Filters < 1.2 - SQL Injection

critical

The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

CVSS:
9.8
Affected:
up to 1.1
Fixed in:
1.2
Disclosed:
Feb 25, 2016

CVE-2016-11000 on NVD →

Export All Posts, Products, Orders, Refunds &amp; Users [wp-ultimate-exporter] < 1.2

unknown

This plugin is prone to an SQL injection vulnerability. It allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Feb 25, 2016

WP Ultimate Exporter < 1.1 - Reflected Cross-Site Scripting

medium

The WP Ultimate Exporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘export_name’ and 'export_post_type_name' parameters in versions before 1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

CVSS:
6.1
Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Feb 24, 2016

Export All Posts, Products, Orders, Refunds &amp; Users [wp-ultimate-exporter] < 1.1

unknown

The WP Ultimate Exporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘export_name’ and 'export_post_type_name' parameters in versions before 1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Feb 24, 2016

Export All Posts, Products, Orders, Refunds &amp; Users [wp-ultimate-exporter] < 1.1

unknown

This plugin is prone to a cross site scripting vulnerability, because "export_name" and "export_post_type_name" parameters are not sanitized. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Feb 24, 2016

Export All Posts, Products, Orders, Refunds &amp; Users [wp-ultimate-exporter] < 1.1

unknown

The Export WordPress Data with Advanced Filters WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.1
Fixed in:
1.1

Export All Posts, Products, Orders, Refunds &amp; Users [wp-ultimate-exporter] < 2.14

unknown
Affected:
up to 2.14
Fixed in:
2.14

CVE-2025-2332 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database