Advanced Order Export For WooCommerce
woo-order-export-lite · plugin
Known security vulnerabilities for Advanced Order Export For WooCommerce. Find out in seconds which version runs on your site with WP Lens.
9 known vulnerabilities
2 critical · 5 exploitable without logging in · 1 with public exploit code · latest Jun 25, 2026
Listed on wordpress.org · latest 4.1.0 · last updated Jun 8, 2026 · 100K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 9.8
CVE-2024-10828unauthenticated≤ 3.5.5
Advanced Order Export For WooCommerce <= 3.5.5 - Unauthenticated PHP Object Injection via Order Details
- Critical 9.1
CVE-2024-31266high privilege≤ 3.4.4
WordPress Advanced Order Export For WooCommerce plugin <= 3.4.4 - Remote Code Execution (RCE) vulnerability
- High 7.8
CVE-2018-11525unauthenticated · needs a click
The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
- High 7.1
CVE-2026-56042customer+≤ 4.0.9
WordPress Advanced Order Export For WooCommerce plugin <= 4.0.9 - Cross Site Scripting (XSS) vulnerability
- Medium 6.5
CVE-2022-40128unauthenticated · needs a click≤ 3.3.2
WordPress Advanced Order Export For WooCommerce plugin <= 3.3.2 - Cross-Site Request Forgery (CSRF) vulnerability
- Medium 6.1
CVE-2021-27349unauthenticated · needs a click
Advanced Order Export before 3.1.8 for WooCommerce allows XSS, a different vulnerability than CVE-2020-11727.
- Medium 6.1
CVE-2020-11727unauthenticated · needs a click
A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordPress allows remote a
- Medium 4.9
CVE-2026-11360shop manager+≤ 4.0.10
Advanced Order Export For WooCommerce <= 4.0.10 - Authenticated (Shop Manager+) SQL Injection via 'sort_direction' Parameter
- Medium 4.8
CVE-2022-35275shop manager+≤ 3.3.1
WordPress Advanced Order Export For WooCommerce plugin <= 3.3.1 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).