CVE-2015-20067: Wp Attachment Export Project Wp Attachment Export

High severity, CVSS 7.5. EPSS: 7.7% chance of exploitation in the next 30 days.

The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data that holds all the details of attachments/posts on a Wordpress

Affected products

Published 2021-11-01. Last modified 2026-06-17.