Web / CMS

Remote Code Execution

WP ALL Export Pro < 1.7.9 - Authenticated Code Injection

WP ALL Export Pro < 1.7.9 – Authenticated Code Injection The plugin does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has

7.2
/ 10
High
CVSS v3.1
ADVISORY ID
PS62
PUBLISHED
2023-02-06
CVE IDs
CVE-2022-3394
VENDORS
Soflyy
PUBLIC EXPLOIT
PoC public
CWE
CWE-94
PRODUCT
WP ALL Export Pro (WordPress plugin)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

WP ALL Export Pro < 1.7.9 – Authenticated Code Injection

The plugin does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on the site. By default only administrators can run exports, but the privilege can be delegated to lower privileged users.

Vulnerability details

Vulnerability details

CVE-2022-3394
CWE-94
High | 7.2

WP ALL Export Pro < 1.7.9 – Authenticated Code Injection The plugin does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary

Auth:
Administrative privileges (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2022-08-18 Reported On

2022-10-03 Made Public On

2022-08-30 Fixed On

Credits

Sanjay Das