CVE-2025-54029: WordPress WooCommerce csv import export Plugin <= 2.0.6 - Arbitrary File Deletion Vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in extendons WooCommerce csv import export extendons-eo-wooimport-export allows Path Traversal.This issue affects WooCommerce csv import export: from n/a through <= 2.0.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54029?
CVE-2025-54029 is classified as a high-severity vulnerability due to its potential for path traversal attacks that could compromise file security.
How do I fix CVE-2025-54029?
To fix CVE-2025-54029, upgrade the extendons WooCommerce csv import export plugin to version 2.0.7 or later.
What systems are affected by CVE-2025-54029?
CVE-2025-54029 affects all versions of the extendons WooCommerce csv import export plugin up to and including version 2.0.6.
What type of vulnerability is CVE-2025-54029?
CVE-2025-54029 is an improper limitation of a pathname to a restricted directory vulnerability, commonly known as a path traversal vulnerability.
Can CVE-2025-54029 lead to data exposure?
Yes, CVE-2025-54029 can potentially lead to unauthorized access to sensitive files on the server, resulting in data exposure.