Product Lister for eBay Security & Risk Analysis

wordpress.org/plugins/product-lister-ebay

The ‘Product Lister for eBay’ easily empowers you with effective and efficient product optimization from the WooCommerce store to the eBay marketplace …

60 active installs v2.0.9 PHP 5.6.0+ WP 5.6+ Updated Mar 14, 2024
ebayebay-listerebay-productsebay-uploadebay-woocommerce
57
C · Use Caution
CVEs total1
Unpatched1
Last CVEApr 21, 2025
Safety Verdict

Is Product Lister for eBay Safe to Use in 2026?

Use With Caution

Score 57/100

Product Lister for eBay has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Apr 21, 2025Updated 2yr ago
Risk Assessment

The "product-lister-ebay" v2.0.9 plugin exhibits a mixed security posture. While it demonstrates good practices like a high percentage of prepared SQL statements and properly escaped outputs, significant concerns arise from its attack surface. A large number of AJAX handlers (15 out of 16) lack proper authentication checks, creating a substantial entry point for unauthorized actions. The taint analysis reveals 7 high-severity flows with unsanitized paths, indicating potential vulnerabilities that could be exploited if user-supplied data is not handled carefully. The plugin's vulnerability history is a major red flag, with a known critical CVE for Improper Control of Filename for Include/Require Statement (PHP Remote File Inclusion) that remains unpatched. This historical pattern of a critical RFI vulnerability suggests a recurring weakness in how file operations or include statements are managed, which, coupled with the high-severity taint flows and unprotected AJAX endpoints, creates a dangerous environment for exploitation.

Despite the positive aspects of SQL and output sanitization, the unpatched critical vulnerability and the numerous unprotected AJAX handlers represent critical weaknesses. The presence of a PHP RFI vulnerability in its history, especially one that is unpatched, is a severe risk that significantly overshadows the plugin's strengths. The taint analysis further highlights potential risks that, when combined with the lack of authorization on many AJAX endpoints, could lead to serious security breaches. Users should exercise extreme caution and prioritize updating or replacing this plugin if a patch is not immediately available.

Key Concerns

  • Unpatched critical CVE (PHP RFI)
  • High-severity taint flows (7)
  • Large attack surface without auth (15 AJAX handlers)
  • Bundled libraries (DataTables, Select2) potentially outdated
Vulnerabilities
1

Product Lister for eBay Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Critical
1

1 total CVE

CVE-2025-39384critical · 9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Product Lister for eBay <= 2.0.9 - Unauthenticated Local File Inclusion

Apr 21, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Product Lister for eBay Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
52 prepared
Unescaped Output
59
428 escaped
Nonce Checks
30
Capability Checks
0
File Operations
28
External Requests
0
Bundled Libraries
2

Bundled Libraries

DataTablesSelect2

SQL Query Safety

95% prepared55 total queries

Output Escaping

88% escaped487 total outputs
Data Flows
10 unsanitized

Data Flow Analysis

25 flows10 with unsanitized paths
ced_ebay_create_new_description_template (admin\class-woocommerce-ebay-integration-admin.php:1756)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
15 unprotected

Product Lister for eBay Attack Surface

Entry Points16
Unprotected15

AJAX Handlers 16

authwp_ajax_ced_ebay_filter_productsadmin\class-woocommerce-ebay-integration-admin.php:50
authwp_ajax_ced_ebay_fetch_next_level_categoryincludes\class-woocommerce-ebay-integration.php:153
authwp_ajax_ced_ebay_map_categories_to_storeincludes\class-woocommerce-ebay-integration.php:154
authwp_ajax_ced_ebay_category_refresh_buttonincludes\class-woocommerce-ebay-integration.php:155
authwp_ajax_ced_ebay_process_bulk_actionincludes\class-woocommerce-ebay-integration.php:156
authwp_ajax_ced_ebay_modify_product_data_for_uploadincludes\class-woocommerce-ebay-integration.php:159
authwp_ajax_ced_ebay_get_modifed_product_detailsincludes\class-woocommerce-ebay-integration.php:160
authwp_ajax_ced_ebay_ajax_live_search_categoriesincludes\class-woocommerce-ebay-integration.php:161
authwp_ajax_ced_ebay_remove_category_mappingincludes\class-woocommerce-ebay-integration.php:162
authwp_ajax_ced_ebay_remove_account_from_integrationincludes\class-woocommerce-ebay-integration.php:163
authwp_ajax_ced_ebay_oauth_authorizationincludes\class-woocommerce-ebay-integration.php:164
authwp_ajax_ced_ebay_fetch_oauth_access_codeincludes\class-woocommerce-ebay-integration.php:165
authwp_ajax_ced_ebay_remove_all_profilesincludes\class-woocommerce-ebay-integration.php:167
authwp_ajax_ced_ebay_reset_category_item_specificsincludes\class-woocommerce-ebay-integration.php:168
authwp_ajax_ced_ebay_remove_term_from_profileincludes\class-woocommerce-ebay-integration.php:169
authwp_ajax_ced_ebay_process_profile_bulk_actionincludes\class-woocommerce-ebay-integration.php:170
WordPress Hooks 12
actionced_ebay_refresh_access_token_scheduleadmin\class-woocommerce-ebay-integration-admin.php:49
filtermce_cssadmin\partials\ced_ebay_description_styling.php:331
actionplugins_loadedincludes\class-woocommerce-ebay-integration.php:135
actionadmin_enqueue_scriptsincludes\class-woocommerce-ebay-integration.php:149
actionadmin_enqueue_scriptsincludes\class-woocommerce-ebay-integration.php:150
actionadmin_menuincludes\class-woocommerce-ebay-integration.php:151
filterced_add_marketplace_menus_arrayincludes\class-woocommerce-ebay-integration.php:152
filterwoocommerce_duplicate_product_exclude_metaincludes\class-woocommerce-ebay-integration.php:157
filterced_marketplaces_logged_arrayincludes\class-woocommerce-ebay-integration.php:158
actionadmin_initincludes\class-woocommerce-ebay-integration.php:166
actionnetwork_admin_noticesproduct-lister-ebay.php:51
actionadmin_noticesproduct-lister-ebay.php:130
Maintenance & Trust

Product Lister for eBay Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedMar 14, 2024
PHP min version5.6.0
Downloads6K

Community Trust

Rating62/100
Number of ratings8
Active installs60
Developer Profile

Product Lister for eBay Developer Profile

cedcommerce

21 plugins · 5K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
204 days
View full developer profile
Detection Fingerprints

How We Detect Product Lister for eBay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-lister-ebay/admin/css/woocommerce-ebay-integration-admin.css/wp-content/plugins/product-lister-ebay/admin/css/tailwind.css
Version Parameters
product-lister-ebay/admin/css/woocommerce-ebay-integration-admin.css?ver=product-lister-ebay/admin/css/tailwind.css?ver=

HTML / DOM Fingerprints

CSS Classes
ced_configuration_plugin_main
REST Endpoints
/wp-json/ced_ebay/v1/
FAQ

Frequently Asked Questions about Product Lister for eBay