CVE-2026-103348: WordPress WP Ultimate Exporter plugin <= 3.0 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/wp-ultimate-exporterto a version that resolves this vulnerability.Fixed in 3.1
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs high privileges (PR:H). The issue is remotely reachable (AV:N), requires low attack complexity (AC:L), and does not require user interaction (UI:N).
Are confidentiality, integrity, and availability all at risk?
Yes. The supplied CVSS vector assigns high impact to confidentiality, integrity, and availability (C:H/I:H/A:H), meaning successful exploitation could affect all three.
Which plugin versions are affected?
WP Ultimate Exporter versions through 3.0 are affected. The available data does not identify a fixed version.