What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.4.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.4.1.
Explanation of Vulnerability in Simple Terms
Product Import Export for WooCommerce versions up to 2.4.1 allow administrators to upload files without proper validation. An attacker with admin access can upload malicious files—including PHP scripts—that execute on the server. This grants full control over the site's database, files, and hosted data. Update immediately to a version newer than 2.4.1.
What an attacker can do
Upload and execute malicious files on the server, gaining full control of the site.
Potential impact on your site
A compromised admin account can lead to complete site takeover, data theft, and malware installation.
Conditions required to exploit
Attacker must have WordPress administrator privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities