CVE-2022-1800
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.
- Affected products
- Export Any Wordpress Data To Xml/Csv
- Soflyy Export Any Wordpress Data To Xml\/csv
- < 1.3.5
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 1.3% (67th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2022-06-13
CVE-2022-1800 at NVD
1 known exploit for CVE-2022-1800
Proof-of-concept code and exploit modules indexed by Sploitus