Code Injection Vulnerability Affects Advanced Order Export For WooCommerce
CVE-2024-31266
9.1CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 April 2024
What is CVE-2024-31266?
The vulnerability in AlgolPlus Advanced Order Export for WooCommerce arises from improper controls over code generation, allowing for unauthorized code injection. This flaw potentially exposes systems to malicious code exploits, compromising the integrity and security of web applications utilizing this plugin. Affected users are advised to evaluate their plugin versions and implement security measures to mitigate possible threats. Immediate updates are recommended to safeguard against exploitation.
Affected Version(s)
Advanced Order Export For WooCommerce <= 3.4.4