PT-2025-44950 · Sidngr+1 · Import Export For Woocommerce

·

CVE-2025-12389

·

Published

2025-11-03

·

Updated

2025-11-04

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Import Export For WooCommerce versions prior to 1.6.3
Description Authenticated users with Subscriber-level access and above can perform unauthorized modification of data. This is caused by a missing capability check in the update setting() function, allowing attackers to update the plugin's record setting.
Recommendations Update the plugin to version 1.6.3 or later. As a temporary workaround, restrict access to the update setting() function to prevent unauthorized users from modifying settings.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12389

Affected Products

Import Export For Woocommerce