CVE Database /
CVE-2024-31266
CVE · Critical
CVE-2024-31266 — Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.4.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-31266
|
Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.4.5 |
Improper Control of Generation of Code ('Code Injection') |
Critical
9.1
|
< 3.4.5
|
3.4.5 |
2024-04-05 |
—
|
CVE-2024-31266
The Advanced Order Export For WooCommerce plugin before version 3.4.5 contains a remote code execution vulnerability that could enable an attacker to run arbitrary commands on an affected website and establish unauthorized control. The flaw was discovered by movrment and has been patched in version 3.4.5 and later. Users should update their installations immediately to mitigate the risk of potential website compromise.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings