PT-2025-44950 · Sidngr+1 · Import Export For Woocommerce
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Import Export For WooCommerce versions prior to 1.6.3
Description
Authenticated users with Subscriber-level access and above can perform unauthorized modification of data. This is caused by a missing capability check in the
update setting() function, allowing attackers to update the plugin's record setting.Recommendations
Update the plugin to version 1.6.3 or later.
As a temporary workaround, restrict access to the
update setting() function to prevent unauthorized users from modifying settings.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Import Export For Woocommerce