Executive brief
A vulnerability in the WooCommerce CSV Importer plugin for WordPress allows any registered user to delete critical files from the web server. By exploiting this flaw, an attacker could delete the site's configuration files, potentially leading to a complete site shutdown or allowing the attacker to take over the website. This affects businesses using this plugin to manage product data via CSV files.
Technical details
A path traversal vulnerability exists in WooCommerce CSV Importer version 3.3.6 and below due to insufficient validation of the 'filename' parameter in the 'delete_export_file' AJAX action. An authenticated user (any registered account) can send a crafted POST request containing directory traversal sequences (e.g., ../) to the admin-ajax.php endpoint. This allows the attacker to bypass the intended export directory and delete sensitive system files, such as wp-config.php. Deleting wp-config.php can trigger the WordPress installation process, potentially allowing an attacker to re-install the site and gain administrative control.
Affected products
- WooCommerce WooCommerce CSV Importer <= 3.3.6
Timeline
- 2017-11-23: other: Vulnerability discovered
- 2017-12-29: other: Vendor contacted
- 2018-04-09: disclosed: Exploit published on Exploit-DB
- 2026-05-17: advisory: NVD advisory published