The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 2.1.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to disclose sensitive information or perform unauthorized actions, such as saving advanced plugin settings.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Export WP Page to Static HTML/CSS <= 2.1.9 - Missing Authorization via Multiple AJAX Actions |
Tue, 03 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:50:07.036Z
Reserved: 2023-11-28T16:49:15.827Z
Link: CVE-2023-6369
Updated: 2024-08-02T08:28:21.780Z
Status : Modified
Published: 2024-01-11T09:15:48.380
Modified: 2026-04-08T18:18:36.637
Link: CVE-2023-6369
No data.
OpenCVE Enrichment
No data.