Product Import Export for WooCommerce – Import Export Product CSV Suite <= 2.5.6 - Missing Authorization
medium
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to pe...
- CVSS:
- 4.3
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.7
- Disclosed:
- May 27, 2026
CVE-2026-48971 on NVD →
Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter
high
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.0 via deserialization of untrusted input from the 'form_data' parameter This makes it possible for authenticated attackers, with Administrator-...
- CVSS:
- 7.2
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Mar 25, 2025
CVE-2025-1913 on NVD →
Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
high
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the validate_file() Function. This makes it possible for authenticated attackers, with Administrator-level access and above, to ma...
- CVSS:
- 7.6
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Mar 25, 2025
CVE-2025-1912 on NVD →
Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function
low
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.5.0. This makes it possible for authenticated attackers, with Admini...
- CVSS:
- 2.7
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Mar 25, 2025
CVE-2025-1911 on NVD →
Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function
medium
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the c...
- CVSS:
- 4.9
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Mar 25, 2025
CVE-2025-1769 on NVD →
Product Import Export for WooCommerce <= 2.4.1 - Authenticated(Shop Manager+) Arbitrary File Upload
high
The Product Import Export for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'image_library_attachment' function in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with Shop Manager access and above, to up...
- CVSS:
- 7.2
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.2
- Disclosed:
- Mar 26, 2024
CVE-2024-30231 on NVD →
Product Import Export for WooCommerce <= 2.3.7 - Authenticated(Shop Manager+) Arbitrary File Upload via upload_import_file
high
The Product Import Export for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_import_file' function n all versions up to, and including, 2.3.7. This makes it possible for authenticated attackers, with Shop Manager access and above, to upload ar...
- CVSS:
- 7.2
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.8
- Disclosed:
- Jan 16, 2024
CVE-2024-22152 on NVD →
Product Import Export for WooCommerce <= 1.7.4 - Missing Authorization to CSV Import
medium
The Product Import Export for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.7.4 due to missing capability checks on the woocommerce_csv_import_request AJAX action. This makes it possible for authenticated attackers with minimal permissions, such as subscribers...
- CVSS:
- 4.3
- Affected:
- up to 1.7.5
- Fixed in:
- 1.7.5
- Disclosed:
- Mar 11, 2020
CVE-2020-12074 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database