WordPress security by component
WP All Export
Plugin description
WP All Export is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Feb 18, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
wp-all-exportLatest vulnerability
CVE-2026-1582: WP All Export: Sensitive information exposure
WP All Export is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
| Safe version |
|
||
|---|---|---|---|
| Feb 18, 2026 |
CVE-2026-1582
WP All Export: Sensitive information exposure
WP All Export is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE3.7
NVDPending
|
| Feb 07, 2025 |
CVE-2024-7425
WP ALL Export Pro: Privilege escalation or authentication bypass
WP ALL Export Pro is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE6.8
NVD7.2
|
| Feb 07, 2025 |
CVE-2024-7419
WP ALL Export Pro: Code execution
WP ALL Export Pro is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.3
NVD8.8
|
| Oct 25, 2022 |
CVE-2022-3395
WP All Export Pro: SQL injection
WP All Export Pro is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Oct 25, 2022 |
CVE-2022-3394
WP All Export Pro: A security weakness
WP All Export Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Nov 08, 2021 |
CVE-2021-24708
Export any WordPress data to XML/CSV: Cross-site scripting
Export any WordPress data to XML/CSV is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|