PoC Index

CVE-2023-5886

HIGH 8.8EPSS 0.5%

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserialization, which may lead to remote code execution.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
0.55% chance of exploitation in the next 30 days, 44th percentile
Published
2023-12-18
Updated
2024-08-02

Proof-of-concept exploits (1)

References

Related