CVE-2022-0914 Information
Jun 07, 2022
cve
Description
The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file which the attacker can then download and retrieve the list of titles for example
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Reference
https://wpscan.com/vulnerability/c328be28-75dd-43db-a5b9-c1ba0636c930 cpe:2.3:a:atlasgondal:export_all_urls::::::wordpress::*
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: