Extension WordPress

Vulnérabilités WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel

Cette page rassemble les failles publiées pour WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
1Critiques
7Avec correctif
9,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel

7 fiches

CVE-2026-1582 Faible · 3,7
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel

WP All Export <= 1.4.14 – Unauthenticated Sensitive Information Exposure via PHP Type Juggling

The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.14 via the export download endpoint. This is due to a PHP type juggling vulnerability in the security…

Versions affectées

*-1.4.14

Correctif

1.4.15

Publication

17/02/2026

CVE-2023-5886 Élevée · 8,8
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel

Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 – Cross-Site Request Forgery to PHAR Deserialization

The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version. This is due to missing nonce validation…

Versions affectées

[*, 1.4.1)

Correctif

1.4.1

Publication

24/11/2023

CVE-2023-5882 Élevée · 8,8
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel

Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 – Cross-Site Request Forgery to Remote Code Execution

The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version. This is due to missing nonce validation…

Versions affectées

[*, 1.4.1)

Correctif

1.4.1

Publication

24/11/2023

CVE-2023-4724 Moyenne · 6,4
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel

Export any WordPress data to XML/CSV < 1.4.1 & WP ALL Export Pro < 1.8.6 – Authenticated (Admin+) Remote Code Execution

The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Remote Code Execution in versions up to 1.4.1, and in versions up to 1.8.6 in the PRO version via the 'wp_query' parameter. This makes it…

Versions affectées

[*, 1.4.1)

Correctif

1.4.1

Publication

24/11/2023

Vulnérabilité Moyenne · 6,1
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel

Export any WordPress data to XML/CSV <= 1.3.5 – Reflected Cross-Site Scripting

The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 1.3.5. This makes it…

Versions affectées

*-1.3.5

Correctif

1.3.6

Publication

07/06/2022

CVE-2021-24708 Moyenne · 4,8
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel

WP All Export <= 1.3.0 – Admin+ Stored Cross-Site Scripting

The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputting it in Manage Exports settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the…

Versions affectées

[*, 1.3.1)

Correctif

1.3.1

Publication

06/10/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités