CVE-2023-4724
18.12.2023, 20:15
The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote serverEnginsight
Vendor | Product | Version |
---|---|---|
soflyy | export_any_wordpress_data_to_xml\/csv | 𝑥 < 1.4.0 |
soflyy | wp_all_export | 𝑥 < 1.8.6 |
𝑥
= Vulnerable software versions