Extension WordPress

Vulnérabilités Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export

Cette page rassemble les failles publiées pour Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export, leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
2Critiques
9Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export

9 fiches

CVE-2025-13606 Moyenne · 6,5
Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export

Export All Posts, Products, Orders, Refunds & Users <= 2.19 – Cross-Site Request Forgery to Sensitive Information Exposure

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.19. This is due to missing or incorrect nonce validation on the `parseData`…

Versions affectées

*-2.19

Correctif

2.20

Publication

01/12/2025

CVE-2025-2332 Critique · 9,8
Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export

Export All Posts, Products, Orders, Refunds & Users <= 2.13 – Unauthenticated PHP Object Injection

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of untrusted input in the 'returnMetaValueAsCustomerInput' function. This makes it…

Versions affectées

*-2.13

Correctif

2.14

Publication

26/03/2025

CVE-2024-12315 Élevée · 7,5
Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export

Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 – Information Disclosure Through Unprotected Directory

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to…

Versions affectées

*-2.9.3

Correctif

2.10

Publication

11/02/2025

CVE-2025-24611 Moyenne · 4,9
Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export

WP Ultimate Exporter <= 2.9 – Authenticated (Admin+) Arbitrary File Read

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9. This makes it possible for authenticated attackers, with Administrator-level access and above, to…

Versions affectées

*-2.9

Correctif

2.9.1

Publication

24/01/2025

CVE-2024-56278 Moyenne · 4,1
Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export

WP Ultimate Exporter <= 2.9.1 – Authenticated (Admin+) Remote Code Execution

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above,…

Versions affectées

*-2.9.1

Correctif

2.9.2

Publication

03/01/2025

CVE-2023-2487 Moyenne · 5,3
Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export

WP Ultimate Exporter <= 2.4.1 – Unauthenticated Information Disclosure

The WP Ultimate Exporter plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.4.1 due to insufficient protection on the directory in which exported files are stored in. This can allow unauthenticated…

Versions affectées

*-2.4.1

Correctif

2.4.2

Publication

03/10/2023

CVE-2018-20968 Élevée · 8,8
Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export

Export WordPress Data with Advanced Filters <= 1.4.1 – Cross-Site Request Forgery

The Export WordPress Data with Advanced Filters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1. This is due to missing or incorrect nonce validation on the export_module() function. This makes…

Versions affectées

[*, 1.4.2)

Correctif

1.4.2

Publication

19/12/2018

Vulnérabilité Moyenne · 6,1
Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export

WP Ultimate Exporter < 1.1 – Reflected Cross-Site Scripting

The WP Ultimate Exporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘export_name’ and 'export_post_type_name' parameters in versions before 1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

[*, 1.1)

Correctif

1.1

Publication

24/02/2016

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités