Product Excel Import Export & Bulk Edit for WooCommerce Security & Risk Analysis

wordpress.org/plugins/webd-woocommerce-product-excel-importer-bulk-edit

Bulk Product Editing for Simple WooCommerce Products & Import with Excel.

100 active installs v4.7 PHP 8.1+ WP 3.0.1+ Updated Nov 24, 2024
bulk-editbulk-product-editexcelproduct-importwoocommerce-import
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 10, 2025
Safety Verdict

Is Product Excel Import Export & Bulk Edit for WooCommerce Safe to Use in 2026?

Mostly Safe

Score 70/100

Product Excel Import Export & Bulk Edit for WooCommerce is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Apr 10, 2025Updated 1yr ago
Risk Assessment

The plugin 'webd-woocommerce-product-excel-importer-bulk-edit' version 4.7 presents a mixed security posture. While it demonstrates strengths in its use of prepared statements for all SQL queries and a significant number of file operations, concerns arise from its limited attack surface protection. The presence of two AJAX handlers without authentication checks is a significant vulnerability, creating an open door for unauthorized actions.

The static analysis reveals a critical risk with the use of the `unserialize` function, which can lead to Remote Code Execution if untrusted data is processed. Although taint analysis did not flag critical or high severity flows, the `unserialize` function's inherent danger cannot be overlooked. The relatively low percentage of properly escaped outputs (47%) also suggests a potential for Cross-Site Scripting (XSS) vulnerabilities.

The vulnerability history shows a medium-severity CVE from 2025-04-10, categorized as Cross-Site Scripting. The fact that this vulnerability is currently unpatched is a serious concern. This, combined with the static analysis findings, indicates a pattern of potential security weaknesses that require immediate attention. Overall, while the plugin has some good security practices, the unprotected AJAX endpoints, the dangerous `unserialize` function, and the unpatched historical vulnerability significantly elevate its risk profile.

Key Concerns

  • Unpatched CVE (Medium Severity)
  • AJAX handlers without auth checks
  • Dangerous function: unserialize
  • Low percentage of properly escaped outputs
  • Flow with unsanitized paths
Vulnerabilities
1

Product Excel Import Export & Bulk Edit for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32674medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product Excel Import Export & Bulk Edit for WooCommerce <= 4.7 - Reflected Cross-Site Scripting

Apr 10, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Product Excel Import Export & Bulk Edit for WooCommerce Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
107
96 escaped
Nonce Checks
10
Capability Checks
5
File Operations
97
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$this->{$key} = unserialize(serialize($val));Classes\phpoffice\phpspreadsheet\src\PhpSpreadsheet\Worksheet\Worksheet.php:3489

Output Escaping

47% escaped203 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
editProductsDisplay (bulk_edit_products.php:48)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Product Excel Import Export & Bulk Edit for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_webd_bulk_push_notwebd-woocommerce-product-excel-importer-bulk-edit.php:281
authwp_ajax_webd_bulk_push_notwebd-woocommerce-product-excel-importer-bulk-edit.php:282
WordPress Hooks 5
actionadmin_enqueue_scriptswebd-woocommerce-product-excel-importer-bulk-edit.php:62
actionadmin_menuwebd-woocommerce-product-excel-importer-bulk-edit.php:67
filtercodecabin_deactivate_feedback_form_pluginswebd-woocommerce-product-excel-importer-bulk-edit.php:226
actionadmin_noticeswebd-woocommerce-product-excel-importer-bulk-edit.php:252
actionbefore_woocommerce_initwebd-woocommerce-product-excel-importer-bulk-edit.php:292
Maintenance & Trust

Product Excel Import Export & Bulk Edit for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 24, 2024
PHP min version8.1
Downloads19K

Community Trust

Rating66/100
Number of ratings6
Active installs100
Developer Profile

Product Excel Import Export & Bulk Edit for WooCommerce Developer Profile

WPFactory

63 plugins · 136K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
98 days
View full developer profile
Detection Fingerprints

How We Detect Product Excel Import Export & Bulk Edit for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webd-woocommerce-product-excel-importer-bulk-edit/css/font-awesome.min.css/wp-content/plugins/webd-woocommerce-product-excel-importer-bulk-edit/css/style.css/wp-content/plugins/webd-woocommerce-product-excel-importer-bulk-edit/js/javascript_excel.js/wp-content/plugins/webd-woocommerce-product-excel-importer-bulk-edit/js/javascript_bulk_edit.js/wp-content/plugins/webd-woocommerce-product-excel-importer-bulk-edit/images/webd_woocommerce_product_excel_importer_bulk_edit_pro.png
Version Parameters
/wp-content/plugins/webd-woocommerce-product-excel-importer-bulk-edit/css/style.css?v=1ss/wp-content/plugins/webd-woocommerce-product-excel-importer-bulk-edit/js/javascript_excel.js?v=1s

HTML / DOM Fingerprints

CSS Classes
excel_bulk_wrap_freeexcel_bulk_wrap_free_instructionsVideogopropremium_msgpremium_buttonthe_Contentright_wraprightToLeft+1 more
Data Attributes
data-action="webd_woocommerce_product_excel_importer_bulk_edit_process"data-nonce="wp_rest"data-url="admin-ajax.php"
JS Globals
wpeip_urlwoopeip_url
FAQ

Frequently Asked Questions about Product Excel Import Export & Bulk Edit for WooCommerce