Server-Side Request Forgery in Order Export & Order Import for WooCommerce Plugin by WordPress
CVE-2024-13923
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 March 2025
What is CVE-2024-13923?
The Order Export & Order Import for WooCommerce plugin for WordPress is susceptible to Server-Side Request Forgery, allowing authenticated users with administrative access to issue web requests to arbitrary locations. This vulnerability arises from flawed input validation within the validate_file() function, potentially enabling attackers to access and manipulate data from internal services, posing significant security risks.
Affected Version(s)
Order Export & Order Import for WooCommerce * <= 2.6.0