plugin

Order Import Export For Woocommerce Vulnerabilities

18 known security issues reported for the Order Import Export For Woocommerce WordPress plugin. Most recent disclosed Nov 13, 2025.

5 high 2 medium 1 low

Running Order Import Export For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Order Export &amp; Order Import for WooCommerce [order-import-export-for-woocommerce] <= 2.6.7 (unfixed)

unknown

[en] Missing Authorization vulnerability in WebToffee Order Export & Order Import for WooCommerce order-import-export-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Export & Order Import for WooCommerce: from n/a through <= 2.6.7.

Affected:
up to 2.6.7
Fix:
No patched version reported
Disclosed:
Nov 13, 2025

CVE-2025-64382 on NVD →

Order Export & Order Import for WooCommerce <= 2.6.7 - Missing Authorization

medium

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized ac...

CVSS:
4.3
Affected:
up to 2.6.7
Fixed in:
2.6.8
Disclosed:
Oct 30, 2025

CVE-2025-64382 on NVD →

Order Export &amp; Order Import for WooCommerce [order-import-export-for-woocommerce] < 2.6.1

unknown

[en] The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary lo...

Affected:
up to 2.6.1
Fixed in:
2.6.1
Disclosed:
Mar 20, 2025

CVE-2024-13920 on NVD →

Order Export &amp; Order Import for WooCommerce [order-import-export-for-woocommerce] < 2.6.1

unknown

[en] The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above...

Affected:
up to 2.6.1
Fixed in:
2.6.1
Disclosed:
Mar 20, 2025

CVE-2024-13921 on NVD →

Order Export &amp; Order Import for WooCommerce [order-import-export-for-woocommerce] < 2.6.1

unknown

[en] The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with Administrator-level access an...

Affected:
up to 2.6.1
Fixed in:
2.6.1
Disclosed:
Mar 20, 2025

CVE-2024-13922 on NVD →

Order Export &amp; Order Import for WooCommerce [order-import-export-for-woocommerce] < 2.6.1

unknown

[en] The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbi...

Affected:
up to 2.6.1
Fixed in:
2.6.1
Disclosed:
Mar 20, 2025

CVE-2024-13923 on NVD →

Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function

medium

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log fil...

CVSS:
4.9
Affected:
up to 2.6.0
Fixed in:
2.6.1
Disclosed:
Mar 19, 2025

CVE-2024-13920 on NVD →

Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter

high

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to...

CVSS:
7.2
Affected:
up to 2.6.0
Fixed in:
2.6.1
Disclosed:
Mar 19, 2025

CVE-2024-13921 on NVD →

Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function

low

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with Administrator-level access and abo...

CVSS:
2.7
Affected:
up to 2.6.0
Fixed in:
2.6.1
Disclosed:
Mar 19, 2025

CVE-2024-13922 on NVD →

Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

high

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary...

CVSS:
7.6
Affected:
up to 2.6.0
Fixed in:
2.6.1
Disclosed:
Mar 19, 2025

CVE-2024-13923 on NVD →

Order Export &amp; Order Import for WooCommerce [order-import-export-for-woocommerce] < 2.5.0

unknown

[en] Deserialization of Untrusted Data vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.9.

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
May 16, 2024

CVE-2024-34751 on NVD →

Order Export & Order Import for WooCommerce <= 2.4.9 - Authenticated (Administrator+) PHP Object Injection

high

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.9 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known P...

CVSS:
7.2
Affected:
up to 2.4.9
Fixed in:
2.5.0
Disclosed:
May 14, 2024

CVE-2024-34751 on NVD →

Order Export &amp; Order Import for WooCommerce [order-import-export-for-woocommerce] < 2.4.4

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.3.

Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Jan 24, 2024

CVE-2024-22135 on NVD →

Order Export & Order Import for WooCommerce <= 2.4.3 - Authenticated (Shop Manager+) Arbitrary File Upload via upload_import_file

high

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_import_file function in all versions up to, and including, 2.4.3. This makes it possible for authenticated attackers, with shop manager-level access and above, t...

CVSS:
7.2
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Jan 10, 2024

CVE-2024-22135 on NVD →

WebToffee Plugins <= (Various Versions) - Arbitrary User Creation

high

The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.

CVSS:
8.8
Affected:
up to 1.6.1
Fixed in:
1.6.1
Disclosed:
Mar 11, 2020

CVE-2020-12074 on NVD →

Order Export &amp; Order Import for WooCommerce [order-import-export-for-woocommerce] < 1.6.1

unknown

Cross-Site Request Forgery (CSRF) vulnerability discovered by WordFence in WordPress Order Export & Order Import for WooCommerce plugin (versions <= 1.6.0).

Affected:
up to 1.6.1
Fixed in:
1.6.1
Disclosed:
Mar 11, 2020

Order Export &amp; Order Import for WooCommerce [order-import-export-for-woocommerce] < 1.0.9

unknown

This plugin is prone to an order information disclosure vulnerability. It allows attackers to export all order without being authenticated. Update the plugin.

Affected:
up to 1.0.9
Fixed in:
1.0.9
Disclosed:
Sep 19, 2016

Order Export &amp; Order Import for WooCommerce [order-import-export-for-woocommerce] < 1.0.9

unknown

The Order Export &amp; Order Import for WooCommerce WordPress plugin was affected by an Order Information Disclosure security vulnerability.

Affected:
up to 1.0.9
Fixed in:
1.0.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database