WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers

Export WooCommerce products, orders, customers, categories, tags, subscriptions & more into formatted files like CSV, XML, Excel 2007, XLS, XLSX.

9Reported vulnerabilities
9.8Highest CVSS score
2.8.0Latest version
7,000+Active installs

What to do now

Update Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers to 2.7.7 or later. 9 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 23, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2022-0149 Medium 6.1 2.3% Before 2.7.1 2.7.1 February 7, 2022
CVE-2016-10935 Critical 9.8 2.1% Before 1.8.4 1.8.4 August 27, 2019
CVE-2025-60203 High 8.1 0.4% 2.7.6 and earlier 2.7.7 July 15, 2025
WF-eeae2042-ccad-4e4b-a321-8ea58af9d775 Medium 6.4 1.7.5 and earlier 1.7.6 August 26, 2014
CVE-2025-32539 Medium 6.1 0.4% 2.7.4 and earlier 2.7.5 April 9, 2025
CVE-2024-8793 Medium 6.1 0.4% 2.7.2.1 and earlier 2.7.3 October 1, 2024
CVE-2023-46822 Medium 6.1 0.4% 2.7.2 and earlier 2.7.2.1 October 29, 2023
WF-b59f13b9-8ad3-44a7-90a0-1f959ba55700 Medium 6.1 1.7.5 and earlier 1.7.6 August 26, 2014
WF-a3ecc238-1f84-47fd-96b9-753d4b528c47 Medium 6 2.3.1 and earlier 2.4 January 9, 2020

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.