PLUGIN SECURITY

Is Woo Order Export Lite safe?

Export WooCommerce orders to Excel, CSV, XML, JSON, PDF and HTML. Best free order export plugin for WooCommerce.

What this plugin does

  • Slug: woo-order-export-lite
  • Author: algol.plus
  • 100000+ active installs
  • 100/100 rating (350 reviews on wordpress.org)
  • 4025384 all-time downloads
  • On WordPress.org since 2015-08-10

exportexport ordersorderorder exportwoocommerce

Maintenance status

  • Latest known version: 4.1.0
  • Last updated: 2026-06-08 4:38am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4.0+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

10 known CVEs on file for Woo Order Export Lite. Reported between 2018 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-56042 Advanced Order Export For WooCommerce [woo-order-export-lite] < 4.0.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 4.0.10 4.0.10 2026-06-24 ✓ fixed in latest
CVE-2026-11360 Advanced Order Export For WooCommerce [woo-order-export-lite] < 4.1.0 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 4.9 < 4.1.0 4.1.0 2026-06-17 ✓ fixed in latest
CVE-2024-10828 Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.5.6 Deserialization of Untrusted Data High 8.1 < 3.5.6 3.5.6 2024-11-12 ✓ fixed in latest
CVE-2024-31266 Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.4.5 Improper Control of Generation of Code ('Code Injection') Critical 9.1 < 3.4.5 3.4.5 2024-04-05 ✓ fixed in latest
CVE-2022-40128 Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.3.3 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.3.3 3.3.3 2022-10-20 ✓ fixed in latest
CVE-2022-35275 Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.3.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.3.2 3.3.2 2022-08-09 ✓ fixed in latest
CVE-2021-24169 Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.1.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1.8 3.1.8 2021-03-03 ✓ fixed in latest
CVE-2021-27349 Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.1.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1.8 3.1.8 2021-02-22 ✓ fixed in latest
+ 2 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-11727 Advanced Order Export For WooCommerce [woo-order-export-lite] < 3.1.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1.4 3.1.4 2020-04-08 ✓ fixed in latest
CVE-2018-11525 Advanced Order Export For WooCommerce [woo-order-export-lite] < 1.5.5 Improper Neutralization of Formula Elements in a CSV File High 7.8 < 1.5.5 1.5.5 2018-06-19 ✓ fixed in latest

How to fix it

Keep Woo Order Export Lite updated — 4.1.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.