← WordPress Vulnerabilities
WordPress security by component

WP All Export

WP All Export is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Feb 18, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: wp-all-export

CVE-2026-1582: WP All Export: Sensitive information exposure

WP All Export is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.

PublishedFeb 18, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 18, 2026 CVE-2026-1582
WP All Export: Sensitive information exposure
WP All Export is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE3.7
NVDPending
Feb 07, 2025 CVE-2024-7425
WP ALL Export Pro: Privilege escalation or authentication bypass
WP ALL Export Pro is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE6.8
NVD7.2
Feb 07, 2025 CVE-2024-7419
WP ALL Export Pro: Code execution
WP ALL Export Pro is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.3
NVD8.8
Oct 25, 2022 CVE-2022-3395
WP All Export Pro: SQL injection
WP All Export Pro is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Oct 25, 2022 CVE-2022-3394
WP All Export Pro: A security weakness
WP All Export Pro is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.2
NVD7.2
Nov 08, 2021 CVE-2021-24708
Export any WordPress data to XML/CSV: Cross-site scripting
Export any WordPress data to XML/CSV is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8