Impact
The vulnerability is a missing authorization flaw in the Product Import Export for WooCommerce plugin. It allows attackers to use import/export functions without proper permission checks, enabling the unauthorized viewing, downloading, or modification of product data. This can lead to data breaches, manipulation of catalog entries, or disruption of e‑commerce operations.
Affected Systems
Affected products are WebToffee’s Product Import Export for WooCommerce plugin, versions up to and including 2.5.6. The flaw exists in all earlier releases as well. WordPress sites running any of these versions are at risk.
Risk and Exploitability
The CVSS score of 4.3 classifies the flaw as medium severity. No EPSS score is available, and the vulnerability is not listed in CISA's KEV catalog. Attackers are expected to need at least an authenticated account or benefit from misconfigured role settings; based on the description, it is inferred that the likely attack vector is via the plugin’s web interface, allowing the exploitation of import/export functions over the web.
OpenCVE Enrichment