← back
CVE-2021-24169CWE-79

Advanced Order Export For WooCommerce < 3.1.8 - Reflected Cross-Site Scripting (XSS)

43Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 10%
from disclosure to weapon171 days
Published on NVDApr 5
1st PoC+171d
exploitation probability
10%top 5% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.