Beta

Report

WP ALL Export Pro <= 1.7.8 is vulnerable to Authenticated Code Injection vulnerability

Subscriber
Published
2022-10-02

The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.7.8. This allows low-level attackers (depending on whether they have been given permission to perform exports) to execute code on the server. While the plugin defaults to allow only administrators to perform such exports, they can also delegate this task to lower-privileged users.

CVSS

Score:8.5

Severity:High

Version: 1.7.8

There is a patch available in v1.7.9 and we strongly recommend you update to this version as soon as possible.