CVE-2024-12315

HIGH

WordPress <2.9.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.3 via the exports directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/smack_uci_uploads/exports/ directory which can contain information like exported user data.

Scores

CVSS v3 7.5
EPSS 0.0043
EPSS Percentile 62.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-922
Status published
Products (2)
smackcoders/Export All Posts, Products, Orders, Refunds & Users < 2.9.3
smackcoders/export_all_posts\,_products\,_orders\,_refunds_\&_users < 2.10
Published Feb 12, 2025
Tracked Since Feb 18, 2026