Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-12389 | 2 Sidngr, Wordpress | 2 Import Export For Woocommerce, Wordpress | 2025-11-04 | 4.3 Medium |
| The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_setting() function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's record setting. | ||||
| CVE-2025-48144 | 1 Sidngr | 1 Import Export For Woocommerce | 2025-05-30 | 7.1 High |
| Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce allows Stored XSS. This issue affects Import Export For WooCommerce: from n/a through 1.6.2. | ||||
Page 1 of 1.