Description
The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_setting() function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's record setting.
Problem types
Product status
* (semver)
Timeline
| 2025-11-03: | Disclosed |
Credits
Abhirup Konwar
References
www.wordfence.com/...-54c6-4970-96fd-fab0e81f7034?source=cve
wordpress.org/plugins/import-export-for-woocommerce/