Skip to content
Noroxi

WebToffee records

40 published records for vendor webtoffee.

All records

40 records
  • CVE-2023-3162
    39Monitor

    Stripe Payment Plugin for WooCommerce <= 3.7.7 - Authentication Bypass

    CriticalCVSS 9.8No exploitEPSS 1%

    webtoffee · stripe payment plugin for woocommerceAug 31, 2023

  • WordPress WordPress Comments Import & Export Plugin <= 2.3.1 is vulnerable to CSV Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    webtoffee · wordpress comments import and exportNov 7, 2023

  • WordPress Product Reviews Import Export for WooCommerce Plugin <= 1.4.8 is vulnerable to CSV Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    webtoffee · product reviews import export for woocommerceNov 7, 2023

  • The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts

    HighCVSS 8.8No exploitEPSS 2%

    webtoffee · import export wordpress usersApr 22, 2020

  • WordPress Decorator – WooCommerce Email Customizer Plugin <= 1.2.7 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    webtoffee · decoratorNov 30, 2023

  • The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.

    HighCVSS 7.8Proof of conceptEPSS 5%

    webtoffee · wordpress comments import and exportJun 19, 2018

  • The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, displ

    HighCVSS 7.3Proof of conceptEPSS 5%

    webtoffee · import export wordpress usersAug 23, 2019

  • CVE-2024-0705
    31Monitor

    Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection

    HighCVSS 7.5Proof of conceptEPSS 3%

    webtoffee · stripe payment plugin for woocommerceJan 19, 2024

  • WordPress WordPress Backup & Migration plugin <= 1.4.7 - Sensitive Data Exposure via Log File vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    webtoffee · backup and migrationApr 10, 2024

  • CVE-2025-1970
    30Monitor

    Export and Import Users and Customers <= 2.6.2 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

    HighCVSS 7.6No exploitEPSS 0%

    webtoffee · import export wordpress usersMar 22, 2025

  • CVE-2025-1912
    30Monitor

    Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

    HighCVSS 7.6No exploitEPSS 0%

    webtoffee · product import export for woocommerceMar 26, 2025

  • CVE-2023-6558
    28Monitor

    Export and Import Users and Customers <= 2.4.8 - Authenticated (Shop Manager+) Arbitrary File Upload

    HighCVSS 7.2No exploitEPSS 1%

    webtoffee · import export wordpress usersJan 11, 2024

  • CVE-2023-3459
    28Monitor

    Export and Import Users and Customers <= 2.4.1 - Missing Authorization to Authenticated (Shop Manager) Arbitrary User Password Change

    HighCVSS 7.2No exploitEPSS 1%

    webtoffee · import export wordpress usersJul 17, 2023

  • CVE-2025-1913
    28Monitor

    Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter

    HighCVSS 7.2Proof of conceptEPSS 1%

    webtoffee · product import export for woocommerceMar 26, 2025

  • CVE-2025-1971
    28Monitor

    Export and Import Users and Customers <= 2.6.2 - Authenticated (Admin+) PHP Object Injection via form_data Parameter

    HighCVSS 7.2No exploitEPSS 1%

    webtoffee · import export wordpress usersMar 22, 2025

  • Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter

    HighCVSS 7.2No exploitEPSS 1%

    webtoffee · order export \& order import for woocommerceMar 20, 2025

  • WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.2.1 - Privilege Escalation vulnerability

    HighCVSS 7.2No exploitEPSS 1%

    webtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labelsMay 17, 2024

  • WordPress Product Import Export for WooCommerce plugin <= 2.4.1 - Arbitrary File Upload vulnerability

    HighCVSS 7.2No exploitEPSS 1%

    webtoffee · product import export for woocommerceMar 26, 2024

  • WordPress Order Export & Order Import for WooCommerce Plugin <= 2.4.3 is vulnerable to Arbitrary File Upload

    HighCVSS 7.2No exploitEPSS 1%

    webtoffee · order export \& order import for woocommerceJan 24, 2024

  • WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload

    HighCVSS 7.2No exploitEPSS 1%

    webtoffee · product import export for woocommerceJan 24, 2024

  • CVE-2025-1911
    26Monitor

    Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functi

    MediumCVSS 6.5No exploitEPSS 0%

    webtoffee · product import export for woocommerceMar 26, 2025

  • CVE-2025-1972
    26Monitor

    Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functi

    MediumCVSS 6.5No exploitEPSS 0%

    webtoffee · import export wordpress usersMar 22, 2025

  • Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page

    MediumCVSS 6.5No exploitEPSS 0%

    webtoffee · order export \& order import for woocommerceMar 20, 2025

  • Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

    MediumCVSS 6.5No exploitEPSS 0%

    webtoffee · order export \& order import for woocommerceMar 20, 2025

  • CVE-2023-7068
    26Monitor

    WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.3.0 - Missing Authorization to Order Export

    MediumCVSS 6.5No exploitEPSS 0%

    webtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labelsJan 3, 2024