CVE-2022-0914
The Export All URLs plugin before version 4.3 lacks cross-site request forgery (CSRF) protection on its data export functionality. This vulnerability allows an attacker to trick an authenticated administrator into exporting all posts and pages, including private and draft content, to a CSV file that the attacker can subsequently download and access. The exported data would expose sensitive information such as post titles and other page details that should remain restricted.
Based on public CVE data (MITRE/NVD).