The Advanced Order Export plugin for WordPress has a security issue that allows hackers to inject a harmful code into the system. This can happen when exporting orders if the “Try to convert serialized values” option is turned on. Attackers can then delete important files on the server, which could potentially lead to even more serious attacks.