All 2 CVE vulnerabilities found in Export User Data, with AI-generated Chinese analysis, references, and POCs.
Vendor: qlstudio
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-65552 | WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability CWE-502 | 9.8 | Critical | 2026-08-06 |
| CVE-2026-12240 | Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field CWE-502 | 8.0 | High | 2026-06-30 |
All 2 known CVE vulnerabilities affecting Export User Data with full Chinese analysis, references, and POCs where available.