plugin

Export Woocommerce Vulnerabilities

4 known security issues reported for the Export Woocommerce WordPress plugin. Most recent disclosed Oct 9, 2024.

4 medium

Running Export Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Products, Order & Customers Export for WooCommerce <= 2.0.15 - Reflected Cross-Site Scripting

medium

The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.15. This makes it possible for unauthenticated attackers to inj...

CVSS:
6.1
Affected:
up to 2.0.15
Fixed in:
2.1.0
Disclosed:
Oct 9, 2024

CVE-2024-9377 on NVD →

Products, Order & Customers Export for WooCommerce <= 2.0.11 - Reflected Cross-Site Scripting

medium

The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'alg_export_filter_all_columns' parameter in versions up to, and including, 2.0.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated at...

CVSS:
6.1
Affected:
up to 2.0.11
Fixed in:
2.0.12
Disclosed:
Aug 7, 2024

CVE-2024-43127 on NVD →

Products & Order Export for WooCommerce <= 2.0.7 - Missing Authorization

medium

The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the alg_wc_export_admin_product_preview and alg_wc_export_admin_product_change_date_filter functions in all versions up to, and including, 2.0.7. This makes it possible fo...

CVSS:
4.3
Affected:
up to 2.0.7
Fixed in:
2.0.9
Disclosed:
Jan 10, 2024

CVE-2024-31276 on NVD →

Products, Order & Customers Export for WooCommerce <= 2.0.10 - Reflected Cross-Site Scripting via date parameters

medium

The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple date range parameters in versions up to, and including, 2.0.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...

CVSS:
6.1
Affected:
up to 2.0.10
Fixed in:
2.0.11
Disclosed:
Nov 7, 2023

CVE-2023-47547 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database