PLUGIN SECURITY

Is Wp All Export safe?

Easily export data from any post type, custom field, or taxonomy to a CSV, XML, or Excel file of any custom format. Supports WooCommerce products, ord …

What this plugin does

  • Slug: wp-all-export
  • Author: Soflyy
  • 100000+ active installs
  • 90/100 rating (413 reviews on wordpress.org)
  • 3238174 all-time downloads
  • On WordPress.org since 2014-01-10

exportexport woocommercemigratewordpress csv exportwordpress xml export

Maintenance status

  • Latest known version: 1.5.0
  • Last updated: 2026-06-09 4:53am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

6 known CVEs on file for Wp All Export.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-5886 WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel [wp-all-export] < 1.4.1 Cross-Site Request Forgery (CSRF) High 8.8 < 1.4.1 1.4.1 2023-11-24 ✓ fixed in latest
CVE-2023-4724 WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel [wp-all-export] < 1.4.1 Improper Control of Generation of Code ('Code Injection') High 7.2 < 1.4.1 1.4.1 2023-11-24 ✓ fixed in latest
CVE-2023-5882 WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel [wp-all-export] < 1.4.1 Cross-Site Request Forgery (CSRF) High 8.8 < 1.4.1 1.4.1 2023-11-24 ✓ fixed in latest
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel [wp-all-export] < 1.3.6 Unknown < 1.3.6 1.3.6 2022-06-07 ✓ fixed in latest
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel [wp-all-export] < 1.3.6 Unknown < 1.3.6 1.3.6 2022-06-07 ✓ fixed in latest
CVE-2022-1800 WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel [wp-all-export] < 1.3.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 1.3.5 1.3.5 2022-05-20 ✓ fixed in latest
CVE-2021-24708 WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel [wp-all-export] < 1.3.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.3.1 1.3.1 2021-10-06 ✓ fixed in latest
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel [wp-all-export] < 1.4.15 Unknown < 1.4.15 1.4.15 0000-00-00 ✓ fixed in latest
+ 3 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel [wp-all-export] < 1.3.6 Unknown < 1.3.6 1.3.6 ✓ fixed in latest
WP All Export < 1.3.6 - Reflected Cross-Site Scripting Unknown < 1.3.6 1.3.6 ✓ fixed in latest
CVE-2026-1582 WP All Export < 1.4.15 - Unauthenticated Sensitive Information Exposure via PHP Type Juggling Unknown < 1.4.15 1.4.15 ✓ fixed in latest

How to fix it

Keep Wp All Export updated — 1.5.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.