Extension WordPress
Vulnérabilités Product Import Export for WooCommerce – Import Export Product CSV Suite
Cette page rassemble les failles publiées pour Product Import Export for WooCommerce – Import Export Product CSV Suite, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Product Import Export for WooCommerce – Import Export Product CSV Suite
8 fiches
Product Import Export for WooCommerce – Import Export Product CSV Suite <= 2.5.6 – Missing Authorization
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.6. This makes…
*-2.5.6
2.5.7
27/05/2026
Product Import Export for WooCommerce <= 2.5.0 – Authenticated (Admin+) PHP Object Injection via form_data Parameter
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.0 via deserialization of untrusted input from the 'form_data' parameter…
*-2.5.0
2.5.1
26/03/2025
Product Import Export for WooCommerce <= 2.5.0 – Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the validate_file() Function. This makes it possible for…
*-2.5.0
2.5.1
26/03/2025
Product Import Export for WooCommerce <= 2.5.0 – Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including,…
*-2.5.0
2.5.1
26/03/2025
Product Import Export for WooCommerce <= 2.5.0 – Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.0 via the download_file() function. This makes it possible for authenticated…
*-2.5.0
2.5.1
26/03/2025
Product Import Export for WooCommerce <= 2.4.1 – Authenticated(Shop Manager+) Arbitrary File Upload
The Product Import Export for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'image_library_attachment' function in all versions up to, and including, 2.4.1. This makes it possible for…
*-2.4.1
2.4.2
26/03/2024
Product Import Export for WooCommerce <= 2.3.7 – Authenticated(Shop Manager+) Arbitrary File Upload via upload_import_file
The Product Import Export for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_import_file' function n all versions up to, and including, 2.3.7. This makes it possible for…
*-2.3.7
2.3.8
16/01/2024
Product Import Export for WooCommerce <= 1.7.4 – Missing Authorization to CSV Import
The Product Import Export for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.7.4 due to missing capability checks on the woocommerce_csv_import_request AJAX action. This makes it possible for authenticated attackers…
[*, 1.7.5)
1.7.5
11/03/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.