PDQ CSV

PDQ CSV has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for PDQ CSV has a vendor fix available, so running the current release closes it.

All of these findings were reported by Gaurav Bhosale. The current release is tested up to WordPress 6.4.10.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all PDQ CSV vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2023-31221

PDQ CSV <= 1.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings

Read the full analysis

Vulnerability Records

1 records
PDQ CSV banner
Latestv2.0.0
0.0(0)
0/100
Last Updated
2024-01-09 (3y ago)
Active Installs
0+
Downloads
1,391
Requires WP
4.9.16+
Requires PHP
8.0+
Tested up to
WP 6.4.10
Created
2022-02-03 (5y ago)

This is a pretty darn quick CSV exporter. Export posts, pages, users, taxonomies, or any custom post type faster than you thought was possible, with a user interface that’s easy to navigate. Other exporting plugins may take hours or days to export some data from sites with large databases. This one takes seconds or minutes to export the same data. Define filters to only export records that meet certain criteria, and choose exactly what fields you want to export. Save your settings to run the same or similar exports later. Other exporting plugins may offer filtering, but they break when filtering on numeric values. This one succeeds where they fail. This plugin was developed with speed in mind. Other plugins load files and assets even when they’re not needed, slowing down every page load in your WordPress site. This plugin only loads files and assets when absolutely necessary, keeping your site running smoothly. Only users with the &#8216;export’ capability (such as admins) can use this plugin’s features.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C