CVE · High

CVE-2023-4724 — WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel [wp-all-export] < 1.4.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-4724 WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel [wp-all-export] < 1.4.1 Improper Control of Generation of Code ('Code Injection') High 7.2 < 1.4.1 1.4.1 2023-11-24

CVE-2023-4724

The WP All Export plugin versions before 1.4.1 contain a remote code execution vulnerability that could permit an attacker to execute arbitrary commands on an affected website, potentially leading to complete compromise. Researchers Francesco Marano and Donato Di Pasquale identified this flaw, which enables malicious actors to establish backdoor access and seize control of the site. The vulnerability was addressed in version 1.4.0 and later releases.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.