Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical1
High1
Medium0
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-03-27

CVE-2025-2332 - Export All Posts, Products, Orders, Refunds & Users Plugin

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of untrusted input in the 'returnMetaValueAsCustomerInput' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme…

PLUGIN Export All Posts, Products, Orders, Refunds & Users

CVE-2025-2332

CRITICAL CVSS 9.8 2025-03-27
Threat Entry Updated 2025-02-25

CVE-2024-12315 - Export All Posts Products Orders Refunds Users Plugin

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/smack_uci_uploads/exports/ directory which can contain information like exported user data.

PLUGIN Export All Posts Products Orders Refunds Users

CVE-2024-12315

HIGH CVSS 7.5 2025-02-12
Scroll to top