What the vulnerability does
01Description
Insertion of Sensitive Information Into Sent Data vulnerability in WebFactory Order Export for WooCommerce order-export-and-more-for-woocommerce.This issue affects Order Export for WooCommerce: from n/a through <= 3.23.
Explanation of Vulnerability in Simple Terms
02Summary
Order Export for WooCommerce versions up to 3.23 expose sensitive information through an information disclosure vulnerability. An unauthenticated attacker can access restricted data over the network without user interaction. The vulnerability stems from insufficient access controls on sensitive endpoints. Site administrators should update to a version newer than 3.23 immediately.
What an attacker can do
03Attacker Capabilities
Read sensitive order or export data without authentication.
Potential impact on your site
04Site Impact
Customer order data and export information may be exposed to unauthorized visitors.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
August 26, 2024
CVE published
April 28, 2026
Record updated