216.73.217.22

CVE-2024-7419

· Published 07/02/2025 16:15 · Modified 11/02/2025 19:25

Labels: CVE-2024-7419 2025-02-07CVE-2024-7419CWE-94[email protected]

Essential information

Published
07/02/2025 16:15
Modified
11/02/2025 19:25
Author
Creator
CVSS
8.3 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

CVSS metrics

Description

The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.1 via the custom export fields. This is due to the missing input validation and sanitization of user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary PHP code into form fields that get executed on the server during the export, potentially leading to a complete site compromise. As a prerequisite, the custom export field should include fields containing user-supplied data.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
soflyy / wp all export cpe:2.3:a:soflyy:wp_all_export:*:*:*:*:pro:wordpress:*:*

References