Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export

Information

Software Type Plugin
Software Slug wp-ultimate-exporter (view on wordpress.org)
Software Status Active
Software Author smackcoders
Software Website www.smackcoders.com
Software Downloads 476,633
Software Active Installs 6,000
Software Record Last Updated July 21, 2026

9 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Export All Posts, Products, Orders, Refunds & Users <= 2.19 - Cross-Site Request Forgery to Sensitive Information Exposure Patched CVE-2025-13606 6.5 lucky_buddy December 1, 2025
Export All Posts, Products, Orders, Refunds & Users <= 2.13 - Unauthenticated PHP Object Injection Patched CVE-2025-2332 9.8 Webbernaut March 26, 2025
Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directory Patched CVE-2024-12315 7.5 Webbernaut February 11, 2025
WP Ultimate Exporter <= 2.9 - Authenticated (Admin+) Arbitrary File Read Patched CVE-2025-24611 4.9 I8BL January 24, 2025
WP Ultimate Exporter <= 2.9.1 - Authenticated (Admin+) Remote Code Execution Patched CVE-2024-56278 4.1 Webula January 3, 2025
WP Ultimate Exporter <= 2.4.1 - Unauthenticated Information Disclosure Patched CVE-2023-2487 5.3 Jonas Höbenreich October 3, 2023
Export WordPress Data with Advanced Filters <= 1.4.1 - Cross-Site Request Forgery Patched CVE-2018-20968 8.8 December 19, 2018
Export WordPress Data with Advanced Filters < 1.2 - SQL Injection Patched CVE-2016-11000 9.8 Henri Salo (fgeek) February 25, 2016
WP Ultimate Exporter < 1.1 - Reflected Cross-Site Scripting Patched 6.1 Rahul Pratap Singh February 24, 2016

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation