Security Advisory

CVE-2022-0914

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-04-11 14:40:55
Last updated 2024-08-02 23:47:43
Assigner WPScan
State PUBLISHED

Description

The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example