CVE-2026-2696
The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts) in a predictable pattern using a random 6-digit number. These files are stored in the publicly accessible wp-content/uploads/ directory. As a result, any unauthenticated user can brute-force the filenames to gain access to sensitive data contained within the exported files.
Vendor
-
Product
-
CWE
Yayın Tarihi
2026-04-01 06:16:15
Güncelleme
2026-04-01 14:23:37
Source Identifier
contact@wpscan.com
KEV Date Added
-