Executive brief
The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to Cross-Site Scripting (XSS). This plugin is typically used by e-commerce sites to export order data into various formats. Successful exploitation could allow an attacker to inject malicious scripts into the website, potentially leading to unauthorized actions, redirection of visitors to malicious sites, or the theft of sensitive session information when a privileged user interacts with the affected area.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Algolplus Advanced Order Export For WooCommerce plugin for WordPress in versions up to and including 4.0.9. The vulnerability allows an attacker to inject arbitrary web scripts due to improper input sanitization and output escaping. While the CVSS vector indicates no privileges are required, the advisory notes a 'Customer' privilege association, and exploitation requires user interaction from a privileged user (such as clicking a malicious link or viewing a crafted page). This can lead to script execution in the context of the victim's browser session. The issue has been fixed in version 4.0.10.
Affected products
- Algolplus Advanced Order Export For WooCommerce <= 4.0.9
Timeline
- 2026-05-21: disclosed: Vulnerability reported by ParkHyunWoo
- 2026-06-24: advisory: Advisory published by Patchstack
- 2026-06-25: advisory: NVD CVE record published