What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.3.
Explanation of Vulnerability in Simple Terms
The Order Export & Order Import for WooCommerce plugin allows authenticated administrators to upload files without proper validation. An attacker with admin access can upload malicious files to the server, potentially gaining control of the site. The vulnerability affects versions up to 2.4.3 and requires high-level privileges to exploit.
What an attacker can do
Upload malicious files to the server and execute code on the site.
Potential impact on your site
A compromised admin account can lead to full site takeover, data theft, or malware installation.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities