Extension WordPress
Vulnérabilités Order Export & Order Import for WooCommerce
Cette page rassemble les failles publiées pour Order Export & Order Import for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Order Export & Order Import for WooCommerce
8 fiches
Order Export & Order Import for WooCommerce <= 2.6.7 – Missing Authorization
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.6.7. This makes it possible for…
*-2.6.7
2.6.8
30/10/2025
Order Export & Order Import for WooCommerce <= 2.6.0 – Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access…
*-2.6.0
2.6.1
19/03/2025
Order Export & Order Import for WooCommerce <= 2.6.0 – Authenticated (Admin+) PHP Object Injection via form_data Parameter
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible…
*-2.6.0
2.6.1
19/03/2025
Order Export & Order Import for WooCommerce <= 2.6.0 – Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.0. This makes it…
*-2.6.0
2.6.1
19/03/2025
Order Export & Order Import for WooCommerce <= 2.6.0 – Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level…
*-2.6.0
2.6.1
19/03/2025
Order Export & Order Import for WooCommerce <= 2.4.9 – Authenticated (Administrator+) PHP Object Injection
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.9 via deserialization of untrusted input. This makes it possible for authenticated attackers, with…
*-2.4.9
2.5.0
14/05/2024
Order Export & Order Import for WooCommerce <= 2.4.3 – Authenticated (Shop Manager+) Arbitrary File Upload via upload_import_file
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_import_file function in all versions up to, and including, 2.4.3. This makes it…
*-2.4.3
2.4.4
10/01/2024
WebToffee Plugins <= (Various Versions) – Arbitrary User Creation
The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
[*, 1.6.1)
1.6.1
11/03/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.