plugin

Product Reviews Import Export For Woocommerce Vulnerabilities

5 known security issues reported for the Product Reviews Import Export For Woocommerce WordPress plugin. Most recent disclosed Nov 7, 2023.

1 high 1 medium

Running Product Reviews Import Export For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Product Reviews Import Export for WooCommerce [product-reviews-import-export-for-woocommerce] < 1.4.9 (closed)

unknown

[en] Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee Product Reviews Import Export for WooCommerce.This issue affects Product Reviews Import Export for WooCommerce: from n/a through 1.4.8.

Affected:
up to 1.4.9
Fixed in:
1.4.9
Disclosed:
Nov 7, 2023

CVE-2022-46802 on NVD →

Product Reviews Import Export for WooCommerce <= 1.4.8 - CSV Injection

medium

The Product Reviews Import Export for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.8. This allows attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vu...

CVSS:
4.8
Affected:
up to 1.4.8
Fixed in:
1.4.9
Disclosed:
Dec 9, 2022

CVE-2022-46802 on NVD →

Product Reviews Import Export for WooCommerce [product-reviews-import-export-for-woocommerce] < 1.4.9 (closed)

unknown

The Product Reviews Import Export for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.8. This allows attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vu...

Affected:
up to 1.4.9
Fixed in:
1.4.9
Disclosed:
Dec 9, 2022

WebToffee Plugins <= (Various Versions) - Arbitrary User Creation

high

The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.

CVSS:
8.8
Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Mar 11, 2020

CVE-2020-12074 on NVD →

Product Reviews Import Export for WooCommerce [product-reviews-import-export-for-woocommerce] < 1.3.3 (closed)

unknown

Cross-Site Request Forgery (CSRF) vulnerability discovered by WordFence in WordPress Product Reviews Import Export for WooCommerce plugin (versions <= 1.3.2).

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Mar 11, 2020

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database