The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.1 via the custom export fields. This is due to the missing input validation and sanitization of user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary PHP code into form fields that get executed on the server during the export, potentially leading to a complete site compromise.
As a prerequisite, the custom export field should include fields containing user-supplied data.
As a prerequisite, the custom export field should include fields containing user-supplied data.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53886 | The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.1 via the custom export fields. This is due to the missing input validation and sanitization of user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary PHP code into form fields that get executed on the server during the export, potentially leading to a complete site compromise. As a prerequisite, the custom export field should include fields containing user-supplied data. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 11 Feb 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Soflyy
Soflyy wp All Export |
|
| CPEs | cpe:2.3:a:soflyy:wp_all_export:*:*:*:*:pro:wordpress:*:* | |
| Vendors & Products |
Soflyy
Soflyy wp All Export |
Mon, 10 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Feb 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.1 via the custom export fields. This is due to the missing input validation and sanitization of user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary PHP code into form fields that get executed on the server during the export, potentially leading to a complete site compromise. As a prerequisite, the custom export field should include fields containing user-supplied data. | |
| Title | WP All Export Pro <= 1.9.1 - Unauthenticated Remote Code Execution via Custom Export Fields | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-10T17:14:14.503Z
Reserved: 2024-08-02T13:37:44.695Z
Link: CVE-2024-7419
Updated: 2025-02-10T17:14:09.720Z
Status : Analyzed
Published: 2025-02-07T16:15:39.100
Modified: 2025-02-11T19:25:14.023
Link: CVE-2024-7419
No data.
OpenCVE Enrichment
No data.
EUVD