
CVE-2026-2696 The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts) in a predictable pattern using a random 6-digit … https://www.cve.org/CVERecord?id=CVE-2026-2696
Post summary
The CVE describes a vulnerability in the Export All URLs WordPress plugin where CSV filenames reveal post URLs, including private ones, via a predictable pattern before version 5.1.
