Cyber Posture

CVE-2024-7419

High

Published: 07 February 2025

Published
07 February 2025
Modified
11 February 2025
KEV Added
Patch
CVSS Score 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS Score 0.0171 82.4th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Description

The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.1 via the custom export fields. This is due to the missing input validation and sanitization of user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary PHP code into form fields that get executed on the server during the export, potentially leading to a complete site compromise. As a prerequisite, the custom export field should include fields containing user-supplied data.

Security Summary

CVE-2024-7419 is a remote code execution (RCE) vulnerability affecting the WP ALL Export Pro plugin for WordPress in all versions up to and including 1.9.1. The flaw stems from missing input validation and sanitization of user-supplied data in custom export fields, classified under CWE-94 (Code Injection). It carries a CVSS v3.1 base score of 8.3 (AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H), indicating high severity due to its potential for network-based exploitation with scope change and high impacts across confidentiality, integrity, and availability.

Unauthenticated attackers (PR:N) can exploit this vulnerability by injecting arbitrary PHP code into form fields containing user-supplied data, provided the custom export field includes such fields as a prerequisite. The attack requires high complexity (AC:H) and user interaction (UI:R), such as a site administrator triggering the export process. Successful exploitation leads to PHP code execution on the server, potentially resulting in complete site compromise.

Advisories from Wordfence detail the vulnerability in their threat intelligence report, while the plugin vendor at WP All Import recommends upgrading to a patched version of WP ALL Export Pro beyond 1.9.1 to mitigate the issue. Security practitioners should verify and apply updates promptly, especially for sites using custom export configurations with user-supplied data.

Details

CWE(s)
CWE-94

Affected Products

soflyy
wp all export
≤ 1.9.2

References