Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function
Product Import Export for WooCommerce – Import Export Product CSV Suite
Minimum safe version
2.5.1
Update to 2.5.1 or later to address 8 fixable vulnerabilities
Latest available2.6.3 ✓
Medium 4.9
2025-03-26< 2.5.1
Low 2.7
2025-03-26< 2.5.1
Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function
High 7.6
2025-03-26< 2.5.1
Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
High 7.2
2025-03-26< 2.5.1
WordPress Product Import Export for WooCommerce Plugin <= 2.5.0 is vulnerable to PHP Object Injection
Critical 9.1
2024-03-26< 2.4.2
CVE-2024-30231
High 8.0
2024-01-24< 2.3.8
CVE-2024-22152
High 8.8
2020-04-23< 1.7.5
CVE-2020-12074
N/A
2020-03-11< 1.7.5
WordPress Product Import Export for WooCommerce plugin <= 1.7.4 - Cross-Site Request Forgery (CSRF) vulnerability