Description
The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54572 | The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server |
References
History
Tue, 20 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-05-20T17:58:39.497Z
Reserved: 2023-09-01T17:19:21.190Z
Link: CVE-2023-4724
Updated: 2024-08-02T07:37:59.662Z
Status : Modified
Published: 2023-12-18T20:15:08.453
Modified: 2025-05-20T18:15:44.310
Link: CVE-2023-4724
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD