Vulnerabilities > Smackcoders > High

DATE CVE VULNERABILITY TITLE RISK
2019-09-20 CVE-2016-11000 SQL Injection vulnerability in Smackcoders Ultimate Exporter 1.0/1.1
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
network
low complexity
smackcoders CWE-89
7.5
2019-08-14 CVE-2018-20967 Cross-Site Request Forgery (CSRF) vulnerability in Smackcoders Import ALL Pages, Post Types, Products, Orders, and Users AS XML & CSV
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
network
low complexity
smackcoders CWE-352
8.8