CVE · High

CVE-2024-10828 — Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.5.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10828 Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.5.6 Deserialization of Untrusted Data High 8.1 < 3.5.6 3.5.6 2024-11-12

CVE-2024-10828

The Advanced Order Export For WooCommerce plugin through version 3.5.5 contains a PHP Object Injection vulnerability occurring during order export operations when the "Try to convert serialized values" setting is active, allowing unauthenticated attackers to inject malicious objects through unsafe deserialization of user-supplied data. When combined with an available Property-Oriented Programming chain within the application, attackers can leverage this flaw to delete arbitrary files from the web server, potentially enabling remote code execution through removal of critical files like wp-config.php. This vulnerability has been patched in version 3.5.6.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.