Input validation vulnerability in Order Export & Order Import for WooCommerce 2.4.9

A plugin called “Order Export & Order Import for WooCommerce” used on WordPress websites is at risk of being hacked. This is because it is vulnerable to something called “PHP Object Injection” which basically means that someone could inject a harmful code into the site. This can only be done by someone who has a high level of access to the site, like an Administrator. There is currently no known way for hackers to do this, but if the website has other plugins or themes installed, it could make it easier for them to delete files, get private information, or even run their own code on the site.

Detected in:

Order Export & Order Import for WooCommerce fixed vulnerable versions: >= * <= 2.4.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.