Vulnerabilities > CVE-2021-24708 - Unspecified vulnerability in WP ALL Export Project WP ALL Export

047910
CVSS 4.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
wp-all-export-project

Summary

The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputting it in Manage Exports settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Vulnerable Configurations

Part Description Count
Application
Wp_All_Export_Project
1