Extension WordPress
Vulnérabilités Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export
Cette page rassemble les failles publiées pour Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export
9 fiches
Export All Posts, Products, Orders, Refunds & Users <= 2.19 – Cross-Site Request Forgery to Sensitive Information Exposure
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.19. This is due to missing or incorrect nonce validation on the `parseData`…
*-2.19
2.20
01/12/2025
Export All Posts, Products, Orders, Refunds & Users <= 2.13 – Unauthenticated PHP Object Injection
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of untrusted input in the 'returnMetaValueAsCustomerInput' function. This makes it…
*-2.13
2.14
26/03/2025
Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 – Information Disclosure Through Unprotected Directory
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to…
*-2.9.3
2.10
11/02/2025
WP Ultimate Exporter <= 2.9 – Authenticated (Admin+) Arbitrary File Read
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9. This makes it possible for authenticated attackers, with Administrator-level access and above, to…
*-2.9
2.9.1
24/01/2025
WP Ultimate Exporter <= 2.9.1 – Authenticated (Admin+) Remote Code Execution
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above,…
*-2.9.1
2.9.2
03/01/2025
WP Ultimate Exporter <= 2.4.1 – Unauthenticated Information Disclosure
The WP Ultimate Exporter plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.4.1 due to insufficient protection on the directory in which exported files are stored in. This can allow unauthenticated…
*-2.4.1
2.4.2
03/10/2023
Export WordPress Data with Advanced Filters <= 1.4.1 – Cross-Site Request Forgery
The Export WordPress Data with Advanced Filters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1. This is due to missing or incorrect nonce validation on the export_module() function. This makes…
[*, 1.4.2)
1.4.2
19/12/2018
Export WordPress Data with Advanced Filters < 1.2 – SQL Injection
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
*-1.1
1.2
25/02/2016
WP Ultimate Exporter < 1.1 – Reflected Cross-Site Scripting
The WP Ultimate Exporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘export_name’ and 'export_post_type_name' parameters in versions before 1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
[*, 1.1)
1.1
24/02/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.