Web / CMS

SQL / NoSQL Injection

WP ALL Export Pro < 1.7.9 - Authenticated SQLi

WP ALL Export Pro < 1.7.9 – Authenticated SQLi The plugin does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given…

8.8
/ 10
High
CVSS v3.1
ADVISORY ID
PS63
PUBLISHED
2023-01-18
CVE IDs
CVE-2022-3395
VENDORS
Soflyy
PUBLIC EXPLOIT
PoC public
CWE
CWE-89
PRODUCT
WP ALL Export Pro (WordPress plugin)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

WP ALL Export Pro < 1.7.9 – Authenticated SQLi

The plugin does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on the site. By default only administrators can run exports, but the privilege can be delegated to lower privileged users.

Vulnerability details

Vulnerability details

CVE-2022-3395
CWE-89
High | 8.8

WP ALL Export Pro < 1.7.9 – Authenticated SQLi The plugin does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on

Auth:
Any authenticated user (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2022-08-18 Reported On

2022-10-03 Made Public On

2022-08-30 Fixed On

Credits

Sanjay Das