Description
Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Stored XSS.This issue affects Import Export For WooCommerce: from n/a through <= 1.6.2.
Published: 2025-05-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in the Import Export For WooCommerce plugin allows an attacker to trick an authenticated administrator into sending a crafted request that injects malicious script into data stored by the plugin. Once stored, the payload runs whenever the affected data is rendered, giving the attacker control over the browser context of any user that later views the data. Such a stored XSS can lead to theft of session cookies or hijacking of user accounts. The weakness is categorized as CWE‑352 for cross‑site request forgery.

Affected Systems

The vulnerability affects the WordPress plugin Import Export For WooCommerce from vendor sidngr, in all releases up to and including version 1.6.2. No newer versions are listed as safe, so any installation of these versions remains susceptible.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderately high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying it has not yet been widely exploited or observed in the field. The likely attack vector requires an attacker to convince an administrator to visit a malicious link or otherwise trigger the import action, after which the stored XSS payload executes for all users who subsequently access the injected content.

Generated by OpenCVE AI on April 30, 2026 at 12:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin to a version that removes the flaw (any release newer than 1.6.2).
  • If an upgrade is not immediately possible, disable the Import Export For WooCommerce plugin to prevent the vulnerable import/export functionality from being used.
  • Restrict access to the import/export feature to trusted administrators only, and monitor for suspicious requests that could indicate a CSRF attempt.

Generated by OpenCVE AI on April 30, 2026 at 12:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-15510 Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce allows Stored XSS. This issue affects Import Export For WooCommerce: from n/a through 1.6.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce allows Stored XSS. This issue affects Import Export For WooCommerce: from n/a through 1.6.2. Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Stored XSS.This issue affects Import Export For WooCommerce: from n/a through <= 1.6.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Fri, 30 May 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Sidngr
Sidngr import Export For Woocommerce
CPEs cpe:2.3:a:sidngr:import_export_for_woocommerce:*:*:*:*:*:wordpress:*:*
Vendors & Products Sidngr
Sidngr import Export For Woocommerce

Fri, 16 May 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 May 2025 16:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce allows Stored XSS. This issue affects Import Export For WooCommerce: from n/a through 1.6.2.
Title WordPress Import Export For WooCommerce plugin <= 1.6.2 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Sidngr Import Export For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:52.347Z

Reserved: 2025-05-15T18:01:53.422Z

Link: CVE-2025-48144

cve-icon Vulnrichment

Updated: 2025-05-16T16:23:27.587Z

cve-icon NVD

Status : Modified

Published: 2025-05-16T16:15:45.933

Modified: 2026-04-23T15:30:52.770

Link: CVE-2025-48144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T13:00:13Z

Weaknesses