Skip to content
Noroxi

Advanced Order Export For WooCommerce

woo-order-export-lite · plugin

Known security vulnerabilities for Advanced Order Export For WooCommerce. Find out in seconds which version runs on your site with WP Lens.

9 known vulnerabilities

2 critical · 5 exploitable without logging in · 1 with public exploit code · latest Jun 25, 2026

Listed on wordpress.org · latest 4.1.0 · last updated Jun 8, 2026 · 100K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2024-10828unauthenticated≤ 3.5.5

    Advanced Order Export For WooCommerce <= 3.5.5 - Unauthenticated PHP Object Injection via Order Details

    Critical 9.8
  • CVE-2024-31266high privilege≤ 3.4.4

    WordPress Advanced Order Export For WooCommerce plugin <= 3.4.4 - Remote Code Execution (RCE) vulnerability

    Critical 9.1
  • CVE-2018-11525unauthenticated · needs a click

    The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.

    High 7.8
  • CVE-2026-56042customer+≤ 4.0.9

    WordPress Advanced Order Export For WooCommerce plugin <= 4.0.9 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2022-40128unauthenticated · needs a click≤ 3.3.2

    WordPress Advanced Order Export For WooCommerce plugin <= 3.3.2 - Cross-Site Request Forgery (CSRF) vulnerability

    Medium 6.5
  • CVE-2021-27349unauthenticated · needs a click

    Advanced Order Export before 3.1.8 for WooCommerce allows XSS, a different vulnerability than CVE-2020-11727.

    Medium 6.1
  • CVE-2020-11727unauthenticated · needs a click

    A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordPress allows remote a

    Medium 6.1
  • CVE-2026-11360shop manager+≤ 4.0.10

    Advanced Order Export For WooCommerce <= 4.0.10 - Authenticated (Shop Manager+) SQL Injection via 'sort_direction' Parameter

    Medium 4.9
  • CVE-2022-35275shop manager+≤ 3.3.1

    WordPress Advanced Order Export For WooCommerce plugin <= 3.3.1 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability

    Medium 4.8

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory