Description
Missing Authorization vulnerability in WebToffee Order Export & Order Import for WooCommerce order-import-export-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Export & Order Import for WooCommerce: from n/a through <= 2.6.7.
Published: 2025-11-13
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that lets users bypass intended access restrictions, allowing extraction or manipulation of order export/import data. It originates from insufficient checks on user capability in the Order Export & Order Import for WooCommerce plugin, allowing an attacker who can reach the plugin functionality to view, export, or import order information. The weakness maps to CWE-862 and could compromise confidentiality of customer orders without affecting system integrity directly.

Affected Systems

WebToffee Order Export & Order Import for WooCommerce, versions up to and including 2.6.7. The plugin is typically installed on WordPress sites running WooCommerce. Any site that has not updated beyond 2.6.7 may be vulnerable.

Risk and Exploitability

CVSS of 4.3 indicates moderate impact and availability of exploitation. EPSS is &lt; 1%, meaning actual exploitation instances are currently rare. The vulnerability is not listed in CISA KEV, further indicating low exploitation probability. The attack vector is inferred to be via web requests to the plugin’s admin endpoints, assuming the attacker can authenticate with a user role that can trigger export or import operations. Without proper authorization checks, any authenticated user could exploit the flaw, though unauthenticated attacks are unlikely due to the need to reach the plugin’s protected pages.

Generated by OpenCVE AI on April 29, 2026 at 12:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin to version 2.6.8 or newer, which implements proper authorization checks.
  • Verify that only users with the appropriate capabilities (e.g., manage_woocommerce or higher) can access export/import features; adjust user roles as necessary.
  • If immediate upgrade is not possible, disable the plugin or restrict its admin URLs via WordPress security plugins or server‑level access controls until a patch is applied.

Generated by OpenCVE AI on April 29, 2026 at 12:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Webtoffee
Webtoffee order Export & Order Import For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Webtoffee
Webtoffee order Export & Order Import For Woocommerce
Wordpress
Wordpress wordpress

Thu, 13 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WebToffee Order Export & Order Import for WooCommerce order-import-export-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Export & Order Import for WooCommerce: from n/a through <= 2.6.7.
Title WordPress Order Export & Order Import for WooCommerce plugin <= 2.6.7 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Webtoffee Order Export & Order Import For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:32:53.974Z

Reserved: 2025-10-31T11:25:32.711Z

Link: CVE-2025-64382

cve-icon Vulnrichment

Updated: 2025-11-13T15:24:05.282Z

cve-icon NVD

Status : Deferred

Published: 2025-11-13T10:15:54.323

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-64382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T12:45:11Z

Weaknesses