WordPress Plugin Vulnerabilities

WP Ultimate Exporter < 2.4.2 - Unauthenticated Information Disclosure

Description

The WP Ultimate Exporter plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.4.1 due to insufficient protection on the directory in which exported files are stored in. This can allow unauthenticated attackers to extract sensitive data from accessible log files which can contain information from posts, pages, users, comments, and more. CVE-2023-45066 appears to be a duplicate of this issue.

Affects Plugins

Fixed in 2.4.2

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Jonas Höbenreich
Verified
No

Timeline

Publicly Published
2023-10-03 (about 2 years ago)
Added
2023-11-23 (about 2 years ago)
Last Updated
2024-01-12 (about 2 years ago)

Other