plugin

Order Export And More For Woocommerce Vulnerabilities

4 known security issues reported for the Order Export And More For Woocommerce WordPress plugin. Most recent disclosed Jan 31, 2025.

2 medium

Running Order Export And More For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Order Export for WooCommerce [order-export-and-more-for-woocommerce] < 3.25

unknown

[en] The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.24 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which c...

Affected:
up to 3.25
Fixed in:
3.25
Disclosed:
Jan 31, 2025

CVE-2024-13623 on NVD →

Order Export for WooCommerce <= 3.24 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

medium

The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.24 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can co...

CVSS:
5.9
Affected:
up to 3.24
Fixed in:
3.25
Disclosed:
Jan 30, 2025

CVE-2024-13623 on NVD →

Order Export for WooCommerce [order-export-and-more-for-woocommerce] < 3.24

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in JEM Plugins Order Export for WooCommerce.This issue affects Order Export for WooCommerce: from n/a through 3.23.

Affected:
up to 3.24
Fixed in:
3.24
Disclosed:
Aug 26, 2024

CVE-2024-43259 on NVD →

Order Export for WooCommerce <= 3.23 - Unauthenticated Sensitive Information Exposure

medium

The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.23. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 3.23
Fixed in:
3.24
Disclosed:
Aug 12, 2024

CVE-2024-43259 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database