Description
Missing Authorization vulnerability in brainvireinfo Export All Post Meta export-all-post-meta allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Export All Post Meta: from n/a through <= 1.2.1.
Published: 2025-04-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Export All Post Meta plugin contains a missing authorization flaw that allows any authenticated WordPress user to trigger the plugin’s export functionality without the expected role checks. Because the plugin’s endpoints are not properly constrained by access‑control lists, users can retrieve all post metadata, potentially exposing sensitive data embedded in custom fields, such as authentication tokens or personal information. The weakness is an unauthorized access issue classified as CWE‑862.

Affected Systems

WordPress sites that use the brainvireinfo Export All Post Meta plugin version 1.2.1 or earlier are affected. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate overall risk, and the EPSS score of less than 1% suggests a low probability of exploitation at this time. Based on the description, it is inferred that an attacker must be logged into the site; once authenticated, any user with an admin or contributor role can invoke the export endpoint. The vulnerability is not yet listed in the CISA KEV catalog, and no public exploits have been reported. The lack of proper role checks makes it an efficient vector for a determined attacker to compromise confidentiality.

Generated by OpenCVE AI on May 1, 2026 at 11:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Export All Post Meta to a version newer than 1.2.1 or remove the plugin if no patch is available.
  • Configure WordPress or a security plugin to restrict access to the export endpoint to administrator roles only, ensuring proper role checks are applied.
  • Audit post metadata for sensitive content, back up the database, and monitor logs for unauthorized export activity.

Generated by OpenCVE AI on May 1, 2026 at 11:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9192 Missing Authorization vulnerability in brainvireinfo Export All Post Meta allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Export All Post Meta: from n/a through 1.2.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in brainvireinfo Export All Post Meta allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Export All Post Meta: from n/a through 1.2.1. Missing Authorization vulnerability in brainvireinfo Export All Post Meta export-all-post-meta allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Export All Post Meta: from n/a through <= 1.2.1.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Tue, 01 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in brainvireinfo Export All Post Meta allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Export All Post Meta: from n/a through 1.2.1.
Title WordPress Export All Post Meta Plugin <= 1.2.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:14.759Z

Reserved: 2025-04-01T13:21:00.365Z

Link: CVE-2025-31856

cve-icon Vulnrichment

Updated: 2025-04-01T16:22:31.800Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:27.133

Modified: 2026-04-23T15:28:25.773

Link: CVE-2025-31856

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T11:45:16Z

Weaknesses