CVE-2023-4724: Soflyy Export Any WordPress Data To Xml/csv

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server

Affected products

  • Soflyy Export Any WordPress Data To Xml/csv: before 1.4.0 (fixed in 1.4.0)
  • Soflyy Wp All Export: before 1.8.6 (fixed in 1.8.6)

Published 2023-12-18. Last modified 2026-06-17.