CVE-2024-34751 MEDIUM

CVE-2024-34751: WordPress Order Export & Order Import for WooCommerce plugin <= 2.4.9 - PHP Object Injection vulnerability

Vendor Webtoffee
Product Order Export & Order Import for WooCommerce
Weakness CWE-502 · Unsafe deserialization
Published May 16, 2024
Last update April 28, 2026

CVSS base score

4.4/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Deserialization of Untrusted Data vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for WooCommerce: from n/a through 2.4.9.

Explanation of Vulnerability in Simple Terms

02Summary

The Order Export & Order Import for WooCommerce plugin contains a deserialization vulnerability in versions up to 2.4.9. An authenticated administrator with high privileges can craft malicious serialized data that, when processed by the plugin, may lead to information disclosure or data modification. The attack requires high complexity and does not require user interaction.

What an attacker can do

03Attacker Capabilities

Read or modify sensitive site data through malicious serialized input.

Potential impact on your site

04Site Impact

A malicious admin could extract sensitive data or alter order information without detection.

Conditions required to exploit

05Prerequisites

Administrator account access and high attack complexity; no user interaction required.

Key dates

06Disclosure timeline

May 16, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE