Skip to content

Known CVE

WP Attachment Export < 0.2.4 - Unrestricted File Download

The plugin does not have proper access controls, allowing unauthenticated users to download the XML data that holds all the details of attachments/posts on a Wordpress powered site. This includes details of even privately published posts and password protected posts with their passwords revealed in plain text.

CVE-2015-20067

High2015CVSS 7.5CWE-862

wpscan · packetstorm · seclists · cve2015 · wordpress · wp · wp-plugin · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website