← back
CVE-2022-1800CWE-89

Export any WordPress data to XML/CSV < 1.3.5 - Admin+ SQL Injection

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.3%
exploitation probability
1.3%top 32% of all CVEs
observed exploitation
nono source reports it
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.