Input validation vulnerability in Product Import Export for WooCommerce – Import Export Product CSV Suite 2.5.0

The Product Import Export for WooCommerce plugin for WordPress is not secure and can be exploited by hackers. This can happen when untrusted information is used in the ‘form_data’ section. This can allow attackers with high-level access to inject a PHP Object. However, this vulnerability does not have any impact unless there is another plugin or theme installed that also has a vulnerability. If this is the case, the attacker may be able to delete files, access private information, or even run their own code.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.