XTENDIFY records
12 published records for vendor xtendify.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 41.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-269 Improper Privilege Management1
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-43234No exploit | WordPress Woffice theme <= 5.4.14 - Unauthenticated Account Takeover vulnerabilityxtendify · woffice · CWE-288 | Critical9.8 | — | 0.7% | Dec 16, 2024 |
39Monitor | CVE-2025-2798No exploit | Woffice <= 5.4.21 - Authentication Bypass via Registration Rolextendify · woffice · CWE-269 | Critical9.8 | — | 0.7% | Apr 4, 2025 |
39Monitor | CVE-2024-43153No exploit | WordPress Woffice theme <= 5.4.10 - Unauthenticated Privilege Escalation vulnerabilityxtendify · woffice · CWE-266 | Critical9.8 | — | 0.6% | Aug 13, 2024 |
39Monitor | CVE-2024-37470No exploit | WordPress Woffice Core plugin <= 5.4.8 - Unauthenticated Broken Access Control vulnerabilityxtendify · woffice · CWE-862 | Critical9.8 | — | 0.5% | Nov 1, 2024 |
35Monitor | CVE-2025-2780No exploit | Woffice Core <= 5.4.21 - Authenticated (Subscriber+) Arbitrary File Uploadxtendify · woffice · CWE-434 | High8.8 | — | 0.8% | Apr 4, 2025 |
35Monitor | CVE-2023-46189No exploit | WordPress Google Calendar Events Plugin <= 3.2.5 is vulnerable to Cross Site Request Forgery (CSRF)xtendify · simple calendar · CWE-352 | High8.8 | — | 0.3% | Oct 25, 2023 |
30Monitor | CVE-2025-7694No exploit | Woffice Core <= 5.4.26 - Authenticated (Contributor+) Arbitrary File Deletionxtendify · woffice · CWE-22 | High7.5 | — | 0.9% | Aug 2, 2025 |
24Monitor | CVE-2024-8549No exploit | Simple Calendar – Google Calendar Plugin <= 3.4.2 - Reflected Cross-Site Scriptingxtendify · simple calendar · CWE-79 | Medium6.1 | — | 0.5% | Sep 24, 2024 |
24Monitor | CVE-2024-37472No exploit | WordPress Woffice theme <= 5.4.8 - Reflected Cross Site Scripting (XSS) vulnerabilityxtendify · woffice · CWE-79 | Medium6.1 | — | 0.3% | Jul 4, 2024 |
24Monitor | CVE-2024-37471No exploit | WordPress Woffice Core plugin <= 5.4.8 - Site Wide Reflected Cross Site Scripting (XSS) vulnerabilityxtendify · woffice · CWE-79 | Medium6.1 | — | 0.3% | Jul 4, 2024 |
21Monitor | CVE-2025-2797No exploit | Woffice Core <= 5.4.21 - Cross-Site Request Forgery to User Registration Approvalxtendify · woffice · CWE-352 | Medium5.4 | — | 0.1% | Apr 4, 2025 |
19Monitor | CVE-2023-32738No exploit | WordPress Eonet Manual User Approve Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS)xtendify · eonet manual user approve · CWE-79 | Medium4.8 | — | 0.3% | Oct 27, 2023 |
- CVE-2024-4323439Monitor
WordPress Woffice theme <= 5.4.14 - Unauthenticated Account Takeover vulnerability
CriticalCVSS 9.8No exploitEPSS 1%xtendify · wofficeDec 16, 2024
- CVE-2025-279839Monitor
Woffice <= 5.4.21 - Authentication Bypass via Registration Role
CriticalCVSS 9.8No exploitEPSS 1%xtendify · wofficeApr 4, 2025
- CVE-2024-4315339Monitor
WordPress Woffice theme <= 5.4.10 - Unauthenticated Privilege Escalation vulnerability
CriticalCVSS 9.8No exploitEPSS 1%xtendify · wofficeAug 13, 2024
- CVE-2024-3747039Monitor
WordPress Woffice Core plugin <= 5.4.8 - Unauthenticated Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 1%xtendify · wofficeNov 1, 2024
- CVE-2025-278035Monitor
Woffice Core <= 5.4.21 - Authenticated (Subscriber+) Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 1%xtendify · wofficeApr 4, 2025
- CVE-2023-4618935Monitor
WordPress Google Calendar Events Plugin <= 3.2.5 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%xtendify · simple calendarOct 25, 2023
- CVE-2025-769430Monitor
Woffice Core <= 5.4.26 - Authenticated (Contributor+) Arbitrary File Deletion
HighCVSS 7.5No exploitEPSS 1%xtendify · wofficeAug 2, 2025
- CVE-2024-854924Monitor
Simple Calendar – Google Calendar Plugin <= 3.4.2 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%xtendify · simple calendarSep 24, 2024
- CVE-2024-3747224Monitor
WordPress Woffice theme <= 5.4.8 - Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%xtendify · wofficeJul 4, 2024
- CVE-2024-3747124Monitor
WordPress Woffice Core plugin <= 5.4.8 - Site Wide Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%xtendify · wofficeJul 4, 2024
- CVE-2025-279721Monitor
Woffice Core <= 5.4.21 - Cross-Site Request Forgery to User Registration Approval
MediumCVSS 5.4No exploitEPSS 0%xtendify · wofficeApr 4, 2025
- CVE-2023-3273819Monitor
WordPress Eonet Manual User Approve Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%xtendify · eonet manual user approveOct 27, 2023