CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Soflyy 1Export Any Wordpress Data To Xml/csv Jun 20, 2025 Jan 22, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip file into a publicly accessible directory without sufficiently validating the extracted file type....Show more |
1Soflyy 2Export Any Wordpress Data To Xml/csv Wp All ExportNov 21, 2024 Dec 18, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the abili...Show more |
1Soflyy 2Export Any Wordpress Data To Xml/csv Wp All ExportNov 21, 2024 Dec 18, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged...Show more |
1Soflyy 2Export Any Wordpress Data To Xml/csv Wp All ExportMay 20, 2025 Dec 18, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary co...Show more |
1Soflyy 1Export Any Wordpress Data To Xml/csv Nov 21, 2024 Jun 13, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability. |