Executive brief
The WebToffee Product Import Export plugin for WooCommerce, which helps store owners manage product data, contains a security flaw that fails to properly check user permissions. This could allow a user with low-level access, such as a subscriber, to perform actions or access data they should not be authorized to see. While the risk is considered low, it could lead to unauthorized data exposure within the online store's management interface.
Technical details
A missing authorization vulnerability (CWE-862) exists in the WebToffee Product Import Export for WooCommerce plugin through version 2.5.6. The flaw stems from incorrectly configured access control security levels within the plugin's functional components. An authenticated attacker with low-level privileges (such as a Subscriber) can exploit this to perform actions or access information that should be restricted to higher-privileged roles. The vulnerability is reachable over the network without user interaction. A fix is available in version 2.5.7.
Affected products
- WebToffee Product Import Export for WooCommerce n/a through 2.5.6
Timeline
- 2025-09-30: disclosed: Reported by Legion Hunter
- 2026-05-27: advisory: Published by Patchstack and NVD
- 2026-05-27: patched: Fixed in version 2.5.7