Skip to content
Noroxi

XTENDIFY records

12 published records for vendor xtendify.

All records

12 records
  • WordPress Woffice theme <= 5.4.14 - Unauthenticated Account Takeover vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    xtendify · wofficeDec 16, 2024

  • CVE-2025-2798
    39Monitor

    Woffice <= 5.4.21 - Authentication Bypass via Registration Role

    CriticalCVSS 9.8No exploitEPSS 1%

    xtendify · wofficeApr 4, 2025

  • WordPress Woffice theme <= 5.4.10 - Unauthenticated Privilege Escalation vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    xtendify · wofficeAug 13, 2024

  • WordPress Woffice Core plugin <= 5.4.8 - Unauthenticated Broken Access Control vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    xtendify · wofficeNov 1, 2024

  • CVE-2025-2780
    35Monitor

    Woffice Core <= 5.4.21 - Authenticated (Subscriber+) Arbitrary File Upload

    HighCVSS 8.8No exploitEPSS 1%

    xtendify · wofficeApr 4, 2025

  • WordPress Google Calendar Events Plugin <= 3.2.5 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    xtendify · simple calendarOct 25, 2023

  • CVE-2025-7694
    30Monitor

    Woffice Core <= 5.4.26 - Authenticated (Contributor+) Arbitrary File Deletion

    HighCVSS 7.5No exploitEPSS 1%

    xtendify · wofficeAug 2, 2025

  • CVE-2024-8549
    24Monitor

    Simple Calendar – Google Calendar Plugin <= 3.4.2 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    xtendify · simple calendarSep 24, 2024

  • WordPress Woffice theme <= 5.4.8 - Reflected Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    xtendify · wofficeJul 4, 2024

  • WordPress Woffice Core plugin <= 5.4.8 - Site Wide Reflected Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    xtendify · wofficeJul 4, 2024

  • CVE-2025-2797
    21Monitor

    Woffice Core <= 5.4.21 - Cross-Site Request Forgery to User Registration Approval

    MediumCVSS 5.4No exploitEPSS 0%

    xtendify · wofficeApr 4, 2025

  • WordPress Eonet Manual User Approve Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    xtendify · eonet manual user approveOct 27, 2023