Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical0
High4
Medium1
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2024-11-21

CVE-2023-5886 - Csv Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserialization, which may lead to remote code execution.

PLUGIN Csv

CVE-2023-5886

HIGH CVSS 8.8 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-5882 - Csv Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged in users perform unwanted actions leading to remote code execution.

PLUGIN Csv

CVE-2023-5882

HIGH CVSS 8.8 2023-12-18
Threat Entry Updated 2025-05-20

CVE-2023-4724 - Csv Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server

PLUGIN Csv

CVE-2023-4724

HIGH CVSS 7.2 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2022-1800 - Csv Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.

PLUGIN Csv

CVE-2022-1800

HIGH CVSS 7.2 2022-06-13
Threat Entry Updated 2024-11-21

CVE-2021-24708 - Csv Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputting it in Manage Exports settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Csv

CVE-2021-24708

MEDIUM CVSS 4.8 2021-11-08
Scroll to top