bidorbuy Store Integrator Security & Risk Analysis

wordpress.org/plugins/bidorbuystoreintegrator

Looking for a new place for Your Ecommerce Business?

40 active installs v2.12.0 PHP + WP 4.8+ Updated May 9, 2021
catalogexportproductsvariablesxml
38
D · High Risk
CVEs total2
Unpatched2
Last CVEJan 16, 2026
Safety Verdict

Is bidorbuy Store Integrator Safe to Use in 2026?

High Risk

Score 38/100

bidorbuy Store Integrator carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

2 known CVEs 2 unpatched Last CVE: Jan 16, 2026Updated 4yr ago
Risk Assessment

The bidorbuystoreintegrator plugin v2.12.0 presents a mixed security picture. On the positive side, the static analysis indicates a clean attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. The plugin also demonstrates good practices by largely utilizing prepared statements for its SQL queries and having no external HTTP requests or file operations, which are common vectors for exploitation. However, significant concerns arise from the low percentage of properly escaped output (11%), indicating a high potential for cross-site scripting (XSS) vulnerabilities. Furthermore, the complete absence of nonce checks and a single, unconfirmed capability check on entry points suggest a lack of robust authorization and input validation mechanisms.

The vulnerability history is a major red flag. With two known CVEs, both of which are currently unpatched, the plugin has a history of critical and high-severity issues, specifically Cross-site Scripting and Code Injection. The fact that the last vulnerability was dated in the future (2026-01-16) is highly unusual and likely an anomaly in the data reporting, but the existence of unpatched vulnerabilities remains a severe risk. These past vulnerabilities, coupled with the current code analysis showing insufficient output escaping and weak authorization checks, strongly suggest that this plugin is a high-risk component for any WordPress installation. While the attack surface is small, the potential impact of exploiting existing, unpatched vulnerabilities remains significant.

Key Concerns

  • Two unpatched CVEs
  • Low percentage of properly escaped output
  • Zero nonce checks on entry points
  • Only one capability check found
Vulnerabilities
2

bidorbuy Store Integrator Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2025-68883medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

bidorbuy Store Integrator <= 2.12.0 - Reflected Cross-Site Scripting

Jan 16, 2026Unpatched
CVE-2025-48100high · 7.2Improper Control of Generation of Code ('Code Injection')

bidorbuy Store Integrator <= 2.12.0 - Authenticated (Admin+) Remote Code Execution

Aug 25, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

bidorbuy Store Integrator Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
19 prepared
Unescaped Output
75
9 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

86% prepared22 total queries

Output Escaping

11% escaped84 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<BidorbuyStoreIntegrator> (BidorbuyStoreIntegrator.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

bidorbuy Store Integrator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 31
actionplugins_loadedBidorbuyStoreIntegrator.php:43
actionwoocommerce_after_add_attribute_fieldsBidorbuyStoreIntegrator.php:94
actionwoocommerce_after_edit_attribute_fieldsBidorbuyStoreIntegrator.php:98
actionwoocommerce_after_product_attribute_settingsBidorbuyStoreIntegrator.php:102
actionwoocommerce_attribute_addedBidorbuyStoreIntegrator.php:109
actionwoocommerce_attribute_updatedBidorbuyStoreIntegrator.php:113
actionadmin_initBidorbuyStoreIntegrator.php:117
actionadmin_initBidorbuyStoreIntegrator.php:121
actioninitBidorbuyStoreIntegrator.php:125
actioninitBidorbuyStoreIntegrator.php:129
actionpre_get_postsBidorbuyStoreIntegrator.php:133
actionadmin_noticesBidorbuyStoreIntegrator.php:138
actionadmin_noticesBidorbuyStoreIntegrator.php:144
actionadmin_menuBidorbuyStoreIntegrator.php:150
actionadmin_noticesBidorbuyStoreIntegrator.php:162
filteradmin_body_classBidorbuyStoreIntegrator.php:176
filterstyle_loader_srcBidorbuyStoreIntegrator.php:186
actionadmin_noticesBidorbuyStoreIntegrator.php:476
actionsave_post_productclasses\BidorbuyStoreIntegratorTriggers.php:47
actionwoocommerce_update_product_variationclasses\BidorbuyStoreIntegratorTriggers.php:48
actionwoocommerce_create_product_variationclasses\BidorbuyStoreIntegratorTriggers.php:49
actionwoocommerce_product_bulk_edit_saveclasses\BidorbuyStoreIntegratorTriggers.php:50
actionwoocommerce_product_quick_edit_saveclasses\BidorbuyStoreIntegratorTriggers.php:51
actionwoocommerce_attribute_updatedclasses\BidorbuyStoreIntegratorTriggers.php:52
actionwoocommerce_attribute_deletedclasses\BidorbuyStoreIntegratorTriggers.php:53
actionwoocommerce_tax_rate_addedclasses\BidorbuyStoreIntegratorTriggers.php:54
actionwoocommerce_tax_rate_updatedclasses\BidorbuyStoreIntegratorTriggers.php:55
actionwoocommerce_tax_rate_deletedclasses\BidorbuyStoreIntegratorTriggers.php:56
actioncreate_termclasses\BidorbuyStoreIntegratorTriggers.php:58
actionedited_termsclasses\BidorbuyStoreIntegratorTriggers.php:59
actiondelete_termclasses\BidorbuyStoreIntegratorTriggers.php:60
Maintenance & Trust

bidorbuy Store Integrator Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedMay 9, 2021
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

bidorbuy Store Integrator Developer Profile

extremeidea

5 plugins · 100 total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect bidorbuy Store Integrator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bidorbuystoreintegrator/includes/assets/css/admin.css/wp-content/plugins/bidorbuystoreintegrator/includes/assets/css/styles.css/wp-content/plugins/bidorbuystoreintegrator/includes/assets/js/admin.js/wp-content/plugins/bidorbuystoreintegrator/includes/assets/js/scripts.js
Script Paths
/wp-content/plugins/bidorbuystoreintegrator/includes/assets/js/admin.js/wp-content/plugins/bidorbuystoreintegrator/includes/assets/js/scripts.js
Version Parameters
bidorbuystoreintegrator/includes/assets/css/admin.css?ver=bidorbuystoreintegrator/includes/assets/css/styles.css?ver=bidorbuystoreintegrator/includes/assets/js/admin.js?ver=bidorbuystoreintegrator/includes/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
bobsi-settings-page
HTML Comments
<!-- WARNING: bidorbuy Store Integrator requires WooCommerce to be activated. -->
Data Attributes
data-bidorbuy-token
JS Globals
bobsi_product_idbobsi_variation_idbobsi_ajax_url
REST Endpoints
/wp-json/bidorbuystoreintegrator/v1/products/wp-json/bidorbuystoreintegrator/v1/orders
Shortcode Output
[bidorbuy_product_list][bidorbuy_featured_products][bidorbuy_product_details]
FAQ

Frequently Asked Questions about bidorbuy Store Integrator