Algolplus maintains a focused line of WordPress and WooCommerce commerce plugins that extend e-commerce functionality through order management, dynamic pricing, and payment processing features. Its vulnerability profile centers on web-application input-handling and state-management weakness classes including cross-site request forgery, cross-site scripting, untrusted deserialization, and information exposure, which are characteristic of plugin-based extensions with direct request and database access; the vendor's disclosures frequently acquire public exploit tooling. Defenders should treat updates to these plugins as moderately urgent, particularly where they are exposed to unauthenticated users or manage sensitive transaction data; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Algolplus over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24169MEDIUM This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to re | Apr 5, 2021 | 6.1 | 44 | NO | YES |
CVE-2018-11525HIGH The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection. | Jun 19, 2018 | 7.8 | 35 | NO | YES |
CVE-2026-56042HIGH Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. | Jun 25, 2026 | 7.1 | 29 | NO | NO |
CVE-2024-10828CRITICAL The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.5 via deserialization of untrusted in | Nov 13, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-31266CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in AlgolPlus Advanced Order Export For WooCommerce allows Code Injection.This issue affects Advanced Order E | Apr 25, 2024 | 9.1 | 25 | NO | NO |
CVE-2022-40203HIGH Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.1.5. | Jan 17, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-40128MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Advanced Order Export For WooCommerce plugin <= 3.3.2 on WordPress leading to export file download. | Nov 8, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-41655MEDIUM Auth. (subscriber+) Sensitive Data Exposure vulnerability in Phone Orders for WooCommerce plugin <= 3.7.1 on WordPress. | Nov 18, 2022 | 6.5 | 21 | NO | NO |
CVE-2021-27349MEDIUM Advanced Order Export before 3.1.8 for WooCommerce allows XSS, a different vulnerability than CVE-2020-11727. | Mar 31, 2021 | 6.1 | 21 | NO | NO |
CVE-2026-11360MEDIUM The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_direction' parameter in all versions up to, and including, 4.0.1 | Jun 18, 2026 | 4.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Algolplus.
Media articles that mention a CVE ID that affects a product developed by Algolplus — matched by CVE ID, not by vendor name.