Extension WordPress
Vulnérabilités WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel
Cette page rassemble les failles publiées pour WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel
7 fiches
WP All Export <= 1.4.14 – Unauthenticated Sensitive Information Exposure via PHP Type Juggling
The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.14 via the export download endpoint. This is due to a PHP type juggling vulnerability in the security…
*-1.4.14
1.4.15
17/02/2026
Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 – Cross-Site Request Forgery to PHAR Deserialization
The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version. This is due to missing nonce validation…
[*, 1.4.1)
1.4.1
24/11/2023
Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 – Cross-Site Request Forgery to Remote Code Execution
The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version. This is due to missing nonce validation…
[*, 1.4.1)
1.4.1
24/11/2023
Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 – Authenticated (Admin+) Remote Code Execution
The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Remote Code Execution in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version via the 'wp_query' parameter. This makes it…
[*, 1.4.1)
1.4.1
24/11/2023
Export any WordPress data to XML/CSV <= 1.3.5 – Reflected Cross-Site Scripting
The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.3.5. This makes it…
*-1.3.5
1.3.6
07/06/2022
Export any WordPress data to XML/CSV <= 1.3.4 – Authenticated SQL Injection
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.
*-1.3.4
1.3.5
20/05/2022
WP All Export <= 1.3.0 – Admin+ Stored Cross-Site Scripting
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputting it in Manage Exports settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the…
[*, 1.3.1)
1.3.1
06/10/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.