CVE-2023-4724: Soflyy Export Any WordPress Data To Xml/csv
High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.
The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server
Affected products
- Soflyy Export Any WordPress Data To Xml/csv: before 1.4.0 (fixed in 1.4.0)
- Soflyy Wp All Export: before 1.8.6 (fixed in 1.8.6)
Published 2023-12-18. Last modified 2026-06-17.