PT-2022-21926 · WordPress · Wp All Export Pro

Sanjay Das

·

Published

2022-10-25

·

Updated

2025-05-07

·

CVE-2022-3394

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP All Export Pro versions prior to 1.7.9
Description The issue allows any logged-in user with export privileges to execute arbitrary code on the site, despite the default restriction to administrators. This is because the plugin does not limit certain functionality during exports to users with the Administrator role.
Recommendations For versions prior to 1.7.9, update to version 1.7.9 or later to resolve the issue. As a temporary workaround, consider removing export privileges from lower-privileged users until the update is applied.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-3394

Affected Products

Wp All Export Pro