Extension WordPress

Vulnérabilités Product Import Export for WooCommerce – Import Export Product CSV Suite

Cette page rassemble les failles publiées pour Product Import Export for WooCommerce – Import Export Product CSV Suite, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
0Critiques
8Avec correctif
7,6CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Product Import Export for WooCommerce – Import Export Product CSV Suite

8 fiches

CVE-2026-48971 Moyenne · 4,3
Product Import Export for WooCommerce – Import Export Product CSV Suite

Product Import Export for WooCommerce – Import Export Product CSV Suite <= 2.5.6 – Missing Authorization

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.6. This makes…

Versions affectées

*-2.5.6

Correctif

2.5.7

Publication

27/05/2026

CVE-2025-1913 Élevée · 7,2
Product Import Export for WooCommerce – Import Export Product CSV Suite

Product Import Export for WooCommerce <= 2.5.0 – Authenticated (Admin+) PHP Object Injection via form_data Parameter

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.0 via deserialization of untrusted input from the 'form_data' parameter…

Versions affectées

*-2.5.0

Correctif

2.5.1

Publication

26/03/2025

CVE-2025-1912 Élevée · 7,6
Product Import Export for WooCommerce – Import Export Product CSV Suite

Product Import Export for WooCommerce <= 2.5.0 – Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the validate_file() Function. This makes it possible for…

Versions affectées

*-2.5.0

Correctif

2.5.1

Publication

26/03/2025

CVE-2025-1911 Faible · 2,7
Product Import Export for WooCommerce – Import Export Product CSV Suite

Product Import Export for WooCommerce <= 2.5.0 – Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including,…

Versions affectées

*-2.5.0

Correctif

2.5.1

Publication

26/03/2025

CVE-2025-1769 Moyenne · 4,9
Product Import Export for WooCommerce – Import Export Product CSV Suite

Product Import Export for WooCommerce <= 2.5.0 – Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.0 via the download_file() function. This makes it possible for authenticated…

Versions affectées

*-2.5.0

Correctif

2.5.1

Publication

26/03/2025

CVE-2024-30231 Élevée · 7,2
Product Import Export for WooCommerce – Import Export Product CSV Suite

Product Import Export for WooCommerce <= 2.4.1 – Authenticated(Shop Manager+) Arbitrary File Upload

The Product Import Export for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'image_library_attachment' function in all versions up to, and including, 2.4.1. This makes it possible for…

Versions affectées

*-2.4.1

Correctif

2.4.2

Publication

26/03/2024

CVE-2024-22152 Élevée · 7,2
Product Import Export for WooCommerce – Import Export Product CSV Suite

Product Import Export for WooCommerce <= 2.3.7 – Authenticated(Shop Manager+) Arbitrary File Upload via upload_import_file

The Product Import Export for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_import_file' function n all versions up to, and including, 2.3.7. This makes it possible for…

Versions affectées

*-2.3.7

Correctif

2.3.8

Publication

16/01/2024

CVE-2020-12074 Moyenne · 4,3
Product Import Export for WooCommerce – Import Export Product CSV Suite

Product Import Export for WooCommerce <= 1.7.4 – Missing Authorization to CSV Import

The Product Import Export for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.7.4 due to missing capability checks on the woocommerce_csv_import_request AJAX action. This makes it possible for authenticated attackers…

Versions affectées

[*, 1.7.5)

Correctif

1.7.5

Publication

11/03/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités