plugin

Woocommerce Exporter Vulnerabilities

23 known security issues reported for the Woocommerce Exporter WordPress plugin. Most recent disclosed Nov 6, 2025.

1 critical 1 high 7 medium

Running Woocommerce Exporter on your site? Check whether your installed version is affected.

Scan your site free

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] <= 2.7.6 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Josh Kohlbach Store Exporter woocommerce-exporter allows PHP Local File Inclusion.This issue affects Store Exporter: from n/a through <= 2.7.6.

Affected:
up to 2.7.6
Fix:
No patched version reported
Disclosed:
Nov 6, 2025

CVE-2025-60203 on NVD →

Store Exporter <= 2.7.6 - Unauthenticated Local File Inclusion

high

The Store Exporter plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7.6. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access contr...

CVSS:
8.1
Affected:
up to 2.7.6
Fixed in:
2.7.7
Disclosed:
Jul 15, 2025

CVE-2025-60203 on NVD →

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] <= 2.7.4 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach WooCommerce – Store Exporter allows Reflected XSS. This issue affects WooCommerce – Store Exporter: from n/a through 2.7.4.

Affected:
up to 2.7.4
Fix:
No patched version reported
Disclosed:
Apr 11, 2025

CVE-2025-32539 on NVD →

WooCommerce – Store Exporter <= 2.7.4 - Reflected Cross-Site Scripting

medium

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a...

CVSS:
6.1
Affected:
up to 2.7.4
Fixed in:
2.7.5
Disclosed:
Apr 9, 2025

CVE-2025-32539 on NVD →

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] < 2.7.3

unknown

[en] The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.2.1. This makes it possible for...

Affected:
up to 2.7.3
Fixed in:
2.7.3
Disclosed:
Oct 1, 2024

CVE-2024-8793 on NVD →

Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More <= 2.7.2.1 - Reflected Cross-Site Scripting

medium

The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.2.1. This makes it possible for unaut...

CVSS:
6.1
Affected:
up to 2.7.2.1
Fixed in:
2.7.3
Disclosed:
Sep 30, 2024

CVE-2024-8793 on NVD →

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] < 2.7.2.1

unknown

[en] Unauth. Reflected Cross-Site Scripting') vulnerability in Visser Labs Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin <= 2.7.2 versions.

Affected:
up to 2.7.2.1
Fixed in:
2.7.2.1
Disclosed:
Nov 6, 2023

CVE-2023-46822 on NVD →

WooCommerce - Store Exporter <= 2.7.2 - Reflected Cross-Site Scripting via 'filter'

medium

The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'filter' parameter in all versions up to, and including, 2.7.2 due to insufficient input sanitization and output escaping. This makes it possib...

CVSS:
6.1
Affected:
up to 2.7.2
Fixed in:
2.7.2.1
Disclosed:
Oct 29, 2023

CVE-2023-46822 on NVD →

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] < 2.7.2.1

unknown

The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'filter' parameter in all versions up to, and including, 2.7.2 due to insufficient input sanitization and output escaping. This makes it possib...

Affected:
up to 2.7.2.1
Fixed in:
2.7.2.1
Disclosed:
Oct 29, 2023

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] < 2.7.1

unknown

[en] The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.

Affected:
up to 2.7.1
Fixed in:
2.7.1
Disclosed:
Feb 7, 2022

CVE-2022-0149 on NVD →

WooCommerce – Store Exporter <= 2.7 - Reflected Cross-Site Scripting

medium

The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.

CVSS:
6.1
Affected:
up to 2.7
Fixed in:
2.7.1
Disclosed:
Jan 10, 2022

CVE-2022-0149 on NVD →

WooCommerce - Store Exporter <= 2.3.1 - CSV Injection

medium

The WooCommerce - Store Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.3.1 via the Quick Export' functionality. This allows authenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and o...

CVSS:
6
Affected:
up to 2.3.1
Fixed in:
2.4
Disclosed:
Jan 9, 2020

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] < 2.4

unknown

The WooCommerce - Store Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.3.1 via the Quick Export' functionality. This allows authenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and o...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Jan 9, 2020

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] < 2.4

unknown

CSV Injection vulnerability found by Vishnupriya Ilango (FortiGuard Labs) in WordPress WooCommerce - Store Exporter plugin (versions <= 2.3.1).

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Jan 9, 2020

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] < 1.8.4

unknown

[en] The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Aug 27, 2019

CVE-2016-10935 on NVD →

WooCommerce – Store Exporter <= 1.8.3 - Missing Authorization

critical

The WooCommerce – Store Exporter plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the woo_ce_admin_init function hooked via 'init' in versions up to, and including 1.8.3. This makes it possible for unauthenticated attackers to perform actions like exporting data that may c...

CVSS:
9.8
Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Feb 10, 2016

CVE-2016-10935 on NVD →

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] < 1.7.6

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.7.6
Fixed in:
1.7.6
Disclosed:
Oct 11, 2014

WooCommerce – Store Exporter <= 1.7.5 - Stored Cross-Site Scripting

medium

The WooCommerce – Store Exporter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'export_filename' parameter in versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts t...

CVSS:
6.4
Affected:
up to 1.7.5
Fixed in:
1.7.6
Disclosed:
Aug 26, 2014

WooCommerce Store Exporter <= 1.7.5 - Reflected Cross-Site Scripting

medium

The WooCommerce Store Exporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' & 'dataset' parameters in versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

CVSS:
6.1
Affected:
up to 1.7.5
Fixed in:
1.7.6
Disclosed:
Aug 26, 2014

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] < 1.7.6

unknown

The WooCommerce – Store Exporter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'export_filename' parameter in versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts t...

Affected:
up to 1.7.6
Fixed in:
1.7.6
Disclosed:
Aug 26, 2014

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] < 1.7.6

unknown

The WooCommerce Store Exporter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' & 'dataset' parameters in versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

Affected:
up to 1.7.6
Fixed in:
1.7.6
Disclosed:
Aug 26, 2014

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] < 2.4

unknown

A CSV Injection vulnerability was discovered in WooCommerce - Store Exporter v 2.3.1. It allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible command/code execution.

Affected:
up to 2.4
Fixed in:
2.4

Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers [woocommerce-exporter] < 1.7.6

unknown

The WooCommerce &ndash; Store Exporter WordPress plugin was affected by a Cross Site Scripting (XSS) security vulnerability.

Affected:
up to 1.7.6
Fixed in:
1.7.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database