Order Export & Order Import for WooCommerce [order-import-export-for-woocommerce] <= 2.6.7 (unfixed)
unknown
[en] Missing Authorization vulnerability in WebToffee Order Export & Order Import for WooCommerce order-import-export-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Export & Order Import for WooCommerce: from n/a through <= 2.6.7.
- Affected:
- up to 2.6.7
- Fix:
- No patched version reported
- Disclosed:
- Nov 13, 2025
CVE-2025-64382 on NVD →
Order Export & Order Import for WooCommerce <= 2.6.7 - Missing Authorization
medium
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized ac...
- CVSS:
- 4.3
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.8
- Disclosed:
- Oct 30, 2025
CVE-2025-64382 on NVD →
Order Export & Order Import for WooCommerce [order-import-export-for-woocommerce] < 2.6.1
unknown
[en] The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary lo...
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Mar 20, 2025
CVE-2024-13920 on NVD →
Order Export & Order Import for WooCommerce [order-import-export-for-woocommerce] < 2.6.1
unknown
[en] The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above...
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Mar 20, 2025
CVE-2024-13921 on NVD →
Order Export & Order Import for WooCommerce [order-import-export-for-woocommerce] < 2.6.1
unknown
[en] The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with Administrator-level access an...
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Mar 20, 2025
CVE-2024-13922 on NVD →
Order Export & Order Import for WooCommerce [order-import-export-for-woocommerce] < 2.6.1
unknown
[en] The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbi...
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Mar 20, 2025
CVE-2024-13923 on NVD →
Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function
medium
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log fil...
- CVSS:
- 4.9
- Affected:
- up to 2.6.0
- Fixed in:
- 2.6.1
- Disclosed:
- Mar 19, 2025
CVE-2024-13920 on NVD →
Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter
high
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to...
- CVSS:
- 7.2
- Affected:
- up to 2.6.0
- Fixed in:
- 2.6.1
- Disclosed:
- Mar 19, 2025
CVE-2024-13921 on NVD →
Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function
low
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with Administrator-level access and abo...
- CVSS:
- 2.7
- Affected:
- up to 2.6.0
- Fixed in:
- 2.6.1
- Disclosed:
- Mar 19, 2025
CVE-2024-13922 on NVD →
Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
high
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary...
- CVSS:
- 7.6
- Affected:
- up to 2.6.0
- Fixed in:
- 2.6.1
- Disclosed:
- Mar 19, 2025
CVE-2024-13923 on NVD →
Order Export & Order Import for WooCommerce [order-import-export-for-woocommerce] < 2.5.0
unknown
[en] Deserialization of Untrusted Data vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.9.
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.0
- Disclosed:
- May 16, 2024
CVE-2024-34751 on NVD →
Order Export & Order Import for WooCommerce <= 2.4.9 - Authenticated (Administrator+) PHP Object Injection
high
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.9 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known P...
- CVSS:
- 7.2
- Affected:
- up to 2.4.9
- Fixed in:
- 2.5.0
- Disclosed:
- May 14, 2024
CVE-2024-34751 on NVD →
Order Export & Order Import for WooCommerce [order-import-export-for-woocommerce] < 2.4.4
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.3.
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.4
- Disclosed:
- Jan 24, 2024
CVE-2024-22135 on NVD →
Order Export & Order Import for WooCommerce <= 2.4.3 - Authenticated (Shop Manager+) Arbitrary File Upload via upload_import_file
high
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_import_file function in all versions up to, and including, 2.4.3. This makes it possible for authenticated attackers, with shop manager-level access and above, t...
- CVSS:
- 7.2
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.4
- Disclosed:
- Jan 10, 2024
CVE-2024-22135 on NVD →
WebToffee Plugins <= (Various Versions) - Arbitrary User Creation
high
The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
- CVSS:
- 8.8
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Mar 11, 2020
CVE-2020-12074 on NVD →
Order Export & Order Import for WooCommerce [order-import-export-for-woocommerce] < 1.6.1
unknown
Cross-Site Request Forgery (CSRF) vulnerability discovered by WordFence in WordPress Order Export & Order Import for WooCommerce plugin (versions <= 1.6.0).
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.1
- Disclosed:
- Mar 11, 2020
Order Export & Order Import for WooCommerce [order-import-export-for-woocommerce] < 1.0.9
unknown
This plugin is prone to an order information disclosure vulnerability. It allows attackers to export all order without being authenticated.
Update the plugin.
- Affected:
- up to 1.0.9
- Fixed in:
- 1.0.9
- Disclosed:
- Sep 19, 2016
Order Export & Order Import for WooCommerce [order-import-export-for-woocommerce] < 1.0.9
unknown
The Order Export & Order Import for WooCommerce WordPress plugin was affected by an Order Information Disclosure security vulnerability.
- Affected:
- up to 1.0.9
- Fixed in:
- 1.0.9
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database