Access violation vulnerability in Order Export for WooCommerce 3.24

The Order Export for WooCommerce plugin for WordPress has a security vulnerability that could expose sensitive information. This vulnerability exists in all versions, up to and including 3.24, through the ‘uploads’ directory. This means that attackers who are not logged in could access data that is stored in an insecure manner in the /wp-content/uploads directory. This data may include information about orders that have been exported. The vulnerability is only present when the ‘Order data storage’ setting is set to ‘WordPress posts storage (legacy)’. If the default setting of ‘High-performance order storage’ is enabled, the vulnerability cannot be exploited.

Detected in:

Order Export for WooCommerce fixed vulnerable versions: >= * <= 3.24

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.