High severity7.5NVD Advisory· Published Nov 1, 2021· Updated Jun 17, 2026
CVE-2015-20067
CVE-2015-20067
Description
The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data that holds all the details of attachments/posts on a Wordpress
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:wp_attachment_export_project:wp_attachment_export:*:*:*:*:*:wordpress:*:*Range: <0.2.4
- WordPress/WP Attachment Exportdescription
- Range: <0.2.4
Patches
Vulnerability mechanics
References
3- github.com/espreto/wpsploit/blob/master/modules/auxiliary/scanner/http/wp_attachment_export_file_download.rbnvdExploitThird Party Advisory
- seclists.org/fulldisclosure/2015/Jul/73nvdExploitMailing ListThird Party Advisory
- wpscan.com/vulnerability/d1a9ed65-baf3-4c85-b077-1f37d8c7793anvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.