← back to popular plugins
wordfence / plugin · export-all-urls
Export All URLs
export-all-urls
total installs
50,000
total vulns
1
critical
0
high
1
medium
0
low
0
latest vuln
—
patched
1
unpatched
0
avg time to patch
—
vulnerabilities
(1)
Export All URLs < 5.1 - Unauthenticated Information Exposure
high
✓ patched
cve id
CVE-2026-2696 ↗
cvss score
7.5
cwe
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
published
Apr 2, 2026
The Export All URLs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 5.1 (exclusive). This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.