CVE · Critical

CVE-2024-31266 — Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.4.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-31266 Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.4.5 Improper Control of Generation of Code ('Code Injection') Critical 9.1 < 3.4.5 3.4.5 2024-04-05

CVE-2024-31266

The Advanced Order Export For WooCommerce plugin before version 3.4.5 contains a remote code execution vulnerability that could enable an attacker to run arbitrary commands on an affected website and establish unauthorized control. The flaw was discovered by movrment and has been patched in version 3.4.5 and later. Users should update their installations immediately to mitigate the risk of potential website compromise.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.