cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-ultimate-exporter wp-ultimate-exporter

Direction: ascending
Jun 07, 2024

Export All Posts, Products, Orders, Refunds & Users # CVE-2023-45066

CVE, Research URL

CVE-2023-45066

Date
Nov 30, 2023
Research Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.
Affected versions
Min -, max -.
Status
vulnerable

Export All Posts, Products, Orders, Refunds & Users # CVE-2016-11000

CVE, Research URL

CVE-2016-11000

Date
Sep 20, 2019
Research Description
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
Affected versions
Min -, max -.
Status
vulnerable

Export All Posts, Products, Orders, Refunds & Users # CVE-2018-20968

CVE, Research URL

CVE-2018-20968

Date
Aug 14, 2019
Research Description
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
Affected versions
Min -, max -.
Status
vulnerable

Export All Posts, Products, Orders, Refunds & Users # CVE-2023-2487

CVE, Research URL

CVE-2023-2487

Date
Dec 21, 2023
Research Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.
Affected versions
Min -, max -.
Status
vulnerable
Jan 06, 2025

Export All Posts, Products, Orders, Refunds & Users # CVE-2024-56278

CVE, Research URL

CVE-2024-56278

Date
Jan 07, 2025
Research Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders WP Ultimate Exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through 2.9.1.
Affected versions
Min -, max -.
Status
vulnerable
Jan 26, 2025

Export All Posts, Products, Orders, Refunds & Users # CVE-2025-24611

CVE, Research URL

CVE-2025-24611

Date
Jan 24, 2025
Research Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Smackcoders WP Ultimate Exporter allows Absolute Path Traversal. This issue affects WP Ultimate Exporter: from n/a through 2.9.
Affected versions
Min -, max -.
Status
vulnerable
Feb 16, 2025

Export All Posts, Products, Orders, Refunds & Users # CVE-2024-12315

CVE, Research URL

CVE-2024-12315

Date
Feb 12, 2025
Research Description
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/smack_uci_uploads/exports/ directory which can contain information like exported user data.
Affected versions
Min -, max -.
Status
vulnerable
Mar 28, 2025

Export All Posts, Products, Orders, Refunds & Users # CVE-2025-2332

CVE, Research URL

CVE-2025-2332

Date
Mar 27, 2025
Research Description
The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of untrusted input in the 'returnMetaValueAsCustomerInput' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Affected versions
Min -, max -.
Status
vulnerable