Impact
The vulnerability in the Store Exporter plugin allows an authenticated attacker with shop manager privileges to supply a malicious "filename" value. Through a directory traversal flaw, the plugin can read the contents of any file on the server, potentially exposing sensitive data, and then delete the requested file. The weakness is a classic input validation flaw identified by CWE-22. The impact is confidentiality and integrity compromise of server files, which may contain configuration, credential, or other sensitive information.
Affected Systems
All WordPress sites that use the Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin, version 2.8.0 or earlier. The plugin is authored by jkohlbach and operates within the WooCommerce ecosystem. Sites relying on this plugin for product or order export functionality are directly affected.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity; the EPSS score of less than 1% suggests a very low probability of exploitation in the wild at present, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw requires only authenticated shop manager-level access—a role typically granted to mid-level staff—the attack vector is likely to be internal or from a compromised user account. The attacker would need to craft a request containing a traversal string (e.g., "../../../../etc/passwd") and submit it to the plugin’s export endpoint, leading the server to return or delete the targeted file.
OpenCVE Enrichment