CVE-2024-10828
The Advanced Order Export For WooCommerce plugin through version 3.5.5 contains a PHP Object Injection vulnerability occurring during order export operations when the "Try to convert serialized values" setting is active, allowing unauthenticated attackers to inject malicious objects through unsafe deserialization of user-supplied data. When combined with an available Property-Oriented Programming chain within the application, attackers can leverage this flaw to delete arbitrary files from the web server, potentially enabling remote code execution through removal of critical files like wp-config.php. This vulnerability has been patched in version 3.5.6.
Based on public CVE data (MITRE/NVD).