WebToffee records
40 published records for vendor webtoffee.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 40%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-862 Missing Authorization6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File4
- CWE-918 Server-Side Request Forgery (SSRF)3
The weakness classes this vendor ships most often: where to look.
CWEAll records
40 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-3162No exploit | Stripe Payment Plugin for WooCommerce <= 3.7.7 - Authentication Bypasswebtoffee · stripe payment plugin for woocommerce · CWE-288 | Critical9.8 | — | 1.2% | Aug 31, 2023 |
39Monitor | CVE-2022-45370No exploit | WordPress WordPress Comments Import & Export Plugin <= 2.3.1 is vulnerable to CSV Injectionwebtoffee · wordpress comments import and export · CWE-1236 | Critical9.8 | — | 0.8% | Nov 7, 2023 |
39Monitor | CVE-2022-46802No exploit | WordPress Product Reviews Import Export for WooCommerce Plugin <= 1.4.8 is vulnerable to CSV Injectionwebtoffee · product reviews import export for woocommerce · CWE-1236 | Critical9.8 | — | 0.7% | Nov 7, 2023 |
36Monitor | CVE-2020-12074No exploit | The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts webtoffee · import export wordpress users · CWE-269 | High8.8 | — | 1.7% | Apr 22, 2020 |
35Monitor | CVE-2023-48284No exploit | WordPress Decorator – WooCommerce Email Customizer Plugin <= 1.2.7 is vulnerable to Cross Site Request Forgery (CSRF)webtoffee · decorator · CWE-352 | High8.8 | — | 0.3% | Nov 30, 2023 |
33Monitor | CVE-2018-11526Proof of concept | The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.webtoffee · wordpress comments import and export · CWE-1236 | High7.8 | — | 5.1% | Jun 19, 2018 |
31Monitor | CVE-2019-15092Proof of concept | The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, displwebtoffee · import export wordpress users · CWE-1236 | High7.3 | — | 5.1% | Aug 23, 2019 |
31Monitor | CVE-2024-0705Proof of concept | Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injectionwebtoffee · stripe payment plugin for woocommerce · CWE-89 | High7.5 | — | 2.6% | Jan 19, 2024 |
30Monitor | CVE-2024-31254No exploit | WordPress WordPress Backup & Migration plugin <= 1.4.7 - Sensitive Data Exposure via Log File vulnerabilitywebtoffee · backup and migration · CWE-532 | High7.5 | — | 0.5% | Apr 10, 2024 |
30Monitor | CVE-2025-1970No exploit | Export and Import Users and Customers <= 2.6.2 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Functionwebtoffee · import export wordpress users · CWE-918 | High7.6 | — | 0.4% | Mar 22, 2025 |
30Monitor | CVE-2025-1912No exploit | Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Functionwebtoffee · product import export for woocommerce · CWE-918 | High7.6 | — | 0.4% | Mar 26, 2025 |
28Monitor | CVE-2023-6558No exploit | Export and Import Users and Customers <= 2.4.8 - Authenticated (Shop Manager+) Arbitrary File Uploadwebtoffee · import export wordpress users · CWE-434 | High7.2 | — | 1.4% | Jan 11, 2024 |
28Monitor | CVE-2023-3459No exploit | Export and Import Users and Customers <= 2.4.1 - Missing Authorization to Authenticated (Shop Manager) Arbitrary User Password Changewebtoffee · import export wordpress users · CWE-863 | High7.2 | — | 0.9% | Jul 17, 2023 |
28Monitor | CVE-2025-1913Proof of concept | Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameterwebtoffee · product import export for woocommerce · CWE-502 | High7.2 | — | 0.9% | Mar 26, 2025 |
28Monitor | CVE-2025-1971No exploit | Export and Import Users and Customers <= 2.6.2 - Authenticated (Admin+) PHP Object Injection via form_data Parameterwebtoffee · import export wordpress users · CWE-502 | High7.2 | — | 0.8% | Mar 22, 2025 |
28Monitor | CVE-2024-13921No exploit | Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameterwebtoffee · order export \& order import for woocommerce · CWE-502 | High7.2 | — | 0.7% | Mar 20, 2025 |
28Monitor | CVE-2023-51546No exploit | WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.2.1 - Privilege Escalation vulnerabilitywebtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labels · CWE-269 | High7.2 | — | 0.6% | May 17, 2024 |
28Monitor | CVE-2024-30231No exploit | WordPress Product Import Export for WooCommerce plugin <= 2.4.1 - Arbitrary File Upload vulnerabilitywebtoffee · product import export for woocommerce · CWE-434 | High7.2 | — | 0.6% | Mar 26, 2024 |
28Monitor | CVE-2024-22135No exploit | WordPress Order Export & Order Import for WooCommerce Plugin <= 2.4.3 is vulnerable to Arbitrary File Uploadwebtoffee · order export \& order import for woocommerce · CWE-434 | High7.2 | — | 0.5% | Jan 24, 2024 |
28Monitor | CVE-2024-22152No exploit | WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Uploadwebtoffee · product import export for woocommerce · CWE-434 | High7.2 | — | 0.5% | Jan 24, 2024 |
26Monitor | CVE-2025-1911No exploit | Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functiwebtoffee · product import export for woocommerce · CWE-73 | Medium6.5 | — | 0.4% | Mar 26, 2025 |
26Monitor | CVE-2025-1972No exploit | Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functiwebtoffee · import export wordpress users · CWE-73 | Medium6.5 | — | 0.4% | Mar 22, 2025 |
26Monitor | CVE-2024-13922No exploit | Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page webtoffee · order export \& order import for woocommerce · CWE-73 | Medium6.5 | — | 0.4% | Mar 20, 2025 |
26Monitor | CVE-2024-13923No exploit | Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Functionwebtoffee · order export \& order import for woocommerce · CWE-918 | Medium6.5 | — | 0.4% | Mar 20, 2025 |
26Monitor | CVE-2023-7068No exploit | WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.3.0 - Missing Authorization to Order Exportwebtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labels · CWE-862 | Medium6.5 | — | 0.4% | Jan 3, 2024 |
- CVE-2023-316239Monitor
Stripe Payment Plugin for WooCommerce <= 3.7.7 - Authentication Bypass
CriticalCVSS 9.8No exploitEPSS 1%webtoffee · stripe payment plugin for woocommerceAug 31, 2023
- CVE-2022-4537039Monitor
WordPress WordPress Comments Import & Export Plugin <= 2.3.1 is vulnerable to CSV Injection
CriticalCVSS 9.8No exploitEPSS 1%webtoffee · wordpress comments import and exportNov 7, 2023
- CVE-2022-4680239Monitor
WordPress Product Reviews Import Export for WooCommerce Plugin <= 1.4.8 is vulnerable to CSV Injection
CriticalCVSS 9.8No exploitEPSS 1%webtoffee · product reviews import export for woocommerceNov 7, 2023
- CVE-2020-1207436Monitor
The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts
HighCVSS 8.8No exploitEPSS 2%webtoffee · import export wordpress usersApr 22, 2020
- CVE-2023-4828435Monitor
WordPress Decorator – WooCommerce Email Customizer Plugin <= 1.2.7 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%webtoffee · decoratorNov 30, 2023
- CVE-2018-1152633Monitor
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
HighCVSS 7.8Proof of conceptEPSS 5%webtoffee · wordpress comments import and exportJun 19, 2018
- CVE-2019-1509231Monitor
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, displ
HighCVSS 7.3Proof of conceptEPSS 5%webtoffee · import export wordpress usersAug 23, 2019
- CVE-2024-070531Monitor
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
HighCVSS 7.5Proof of conceptEPSS 3%webtoffee · stripe payment plugin for woocommerceJan 19, 2024
- CVE-2024-3125430Monitor
WordPress WordPress Backup & Migration plugin <= 1.4.7 - Sensitive Data Exposure via Log File vulnerability
HighCVSS 7.5No exploitEPSS 0%webtoffee · backup and migrationApr 10, 2024
- CVE-2025-197030Monitor
Export and Import Users and Customers <= 2.6.2 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
HighCVSS 7.6No exploitEPSS 0%webtoffee · import export wordpress usersMar 22, 2025
- CVE-2025-191230Monitor
Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
HighCVSS 7.6No exploitEPSS 0%webtoffee · product import export for woocommerceMar 26, 2025
- CVE-2023-655828Monitor
Export and Import Users and Customers <= 2.4.8 - Authenticated (Shop Manager+) Arbitrary File Upload
HighCVSS 7.2No exploitEPSS 1%webtoffee · import export wordpress usersJan 11, 2024
- CVE-2023-345928Monitor
Export and Import Users and Customers <= 2.4.1 - Missing Authorization to Authenticated (Shop Manager) Arbitrary User Password Change
HighCVSS 7.2No exploitEPSS 1%webtoffee · import export wordpress usersJul 17, 2023
- CVE-2025-191328Monitor
Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter
HighCVSS 7.2Proof of conceptEPSS 1%webtoffee · product import export for woocommerceMar 26, 2025
- CVE-2025-197128Monitor
Export and Import Users and Customers <= 2.6.2 - Authenticated (Admin+) PHP Object Injection via form_data Parameter
HighCVSS 7.2No exploitEPSS 1%webtoffee · import export wordpress usersMar 22, 2025
- CVE-2024-1392128Monitor
Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter
HighCVSS 7.2No exploitEPSS 1%webtoffee · order export \& order import for woocommerceMar 20, 2025
- CVE-2023-5154628Monitor
WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.2.1 - Privilege Escalation vulnerability
HighCVSS 7.2No exploitEPSS 1%webtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labelsMay 17, 2024
- CVE-2024-3023128Monitor
WordPress Product Import Export for WooCommerce plugin <= 2.4.1 - Arbitrary File Upload vulnerability
HighCVSS 7.2No exploitEPSS 1%webtoffee · product import export for woocommerceMar 26, 2024
- CVE-2024-2213528Monitor
WordPress Order Export & Order Import for WooCommerce Plugin <= 2.4.3 is vulnerable to Arbitrary File Upload
HighCVSS 7.2No exploitEPSS 1%webtoffee · order export \& order import for woocommerceJan 24, 2024
- CVE-2024-2215228Monitor
WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload
HighCVSS 7.2No exploitEPSS 1%webtoffee · product import export for woocommerceJan 24, 2024
- CVE-2025-191126Monitor
Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functi
MediumCVSS 6.5No exploitEPSS 0%webtoffee · product import export for woocommerceMar 26, 2025
- CVE-2025-197226Monitor
Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functi
MediumCVSS 6.5No exploitEPSS 0%webtoffee · import export wordpress usersMar 22, 2025
- CVE-2024-1392226Monitor
Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page
MediumCVSS 6.5No exploitEPSS 0%webtoffee · order export \& order import for woocommerceMar 20, 2025
- CVE-2024-1392326Monitor
Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
MediumCVSS 6.5No exploitEPSS 0%webtoffee · order export \& order import for woocommerceMar 20, 2025
- CVE-2023-706826Monitor
WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.3.0 - Missing Authorization to Order Export
MediumCVSS 6.5No exploitEPSS 0%webtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labelsJan 3, 2024