Arbitrary File Deletion in Order Export & Order Import Plugin for WooCommerce
CVE-2024-13922
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 March 2025
What is CVE-2024-13922?
The Order Export & Order Import for WooCommerce plugin for WordPress has a security flaw where insufficient validation of file paths in the admin_log_page() function could allow authenticated users, particularly those with Administrator-level access, to delete arbitrary log files from the server. All versions up to and including 2.6.0 are affected, exposing the system to potential data loss and other security risks as unauthorized file deletions could disrupt operations or expose sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Order Export & Order Import for WooCommerce * <= 2.6.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved