Sidngr develops a niche e-commerce extension focused on import and export functionality for WooCommerce, with its limited vulnerability surface centered around cross-site request forgery in administrative and data-handling workflows. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sidngr over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-54262CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Upload a Web Shell to a Web Server.This i | Dec 13, 2024 | 9.9 | 28 | NO | NO |
CVE-2025-48144MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Stored XSS.This issue affects Import Export For WooComm | May 16, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-12389MEDIUM The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_setting() function in all | Nov 4, 2025 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sidngr.
Media articles that mention a CVE ID that affects a product developed by Sidngr — matched by CVE ID, not by vendor name.