WebToffee Order Export and Import for WooCommerce Missing Authorization Vulnerability

Vulnerability

A missing authorization vulnerability has been identified in the WebToffee Order Export & Order Import for WooCommerce plugin, specifically in versions through 2.6.7. This vulnerability allows exploitation of improperly configured access control, potentially leading to unauthorized actions or data manipulation.

Impact

Exploitation of this vulnerability could result in unauthorized access or actions being performed on behalf of a user, potentially allowing for the manipulation of order data or other sensitive information.

Added: Nov 13, 2025, 10:19 AM
Updated: Nov 13, 2025, 4:38 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
5.0
exploitability
7.6
remediation
0.0
relevance
1.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.