Impact
The Import Export For WooCommerce WordPress plugin contains a missing capability check in the update_setting() function in all releases up to 1.6.2. This flaw allows authenticated users with Subscriber-level permissions or higher to modify the plugin’s record setting, altering the way export and import operations are handled. While it does not provide direct code execution or data exfiltration, the ability to change critical configuration values can affect the reliability and behavior of an e‑commerce site, potentially disrupting order processing or data exports.
Affected Systems
The vulnerable product is the Import Export For WooCommerce plugin by sidngr. Versions through 1.6.2 are affected; the plugin is used within WordPress installations.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score of less than 1 % suggests low exploitation probability, and the issue is not listed in the CISA KEV catalog. Attackers must be authenticated and have at least Subscriber privileges; the exploitation path is via the plugin’s settings interface accessible to those users.
OpenCVE Enrichment