CVE-2015-20067: Wp Attachment Export Project Wp Attachment Export
High severity, CVSS 7.5. EPSS: 7.7% chance of exploitation in the next 30 days.
The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data that holds all the details of attachments/posts on a Wordpress
Affected products
- Wp Attachment Export Project Wp Attachment Export: before 0.2.4 (fixed in 0.2.4)
Published 2021-11-01. Last modified 2026-06-17.