CVE Database
/

CVE-2023-4724

Back to search

CVE-2023-4724

Published: Dec 18, 2023

Modified: May 20, 2025

PUBLISHED

Description

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server

VendorProductVersions

Unknown

Export any WordPress data to XML/CSV

affected
0 - < 1.4.0

Unknown

WP All Export Pro

affected
0 - < 1.8.6

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now