CVE · Medium

CVE-2022-40128 — Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.3.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-40128 Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.3.3 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.3.3 3.3.3 2022-10-20

CVE-2022-40128

The Advanced Order Export For WooCommerce plugin through version 3.3.2 contains a Cross-Site Request Forgery vulnerability affecting its export download function. The plugin fails to properly validate nonces when processing export requests, allowing unauthenticated attackers to trigger exports with administrator privileges if they can deceive a site admin into clicking a malicious link. This flaw was addressed in version 3.3.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.