Перейти к содержимому
Noroxi

Записи WebToffee

40 опубликованных записей вендора webtoffee.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
40 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

40 записей
  • CVE-2023-3162
    39Наблюдать

    Stripe Payment Plugin for WooCommerce <= 3.7.7 - Authentication Bypass

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    webtoffee · stripe payment plugin for woocommerce31 авг. 2023 г.

  • CVE-2022-45370
    39Наблюдать

    WordPress WordPress Comments Import & Export Plugin <= 2.3.1 is vulnerable to CSV Injection

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    webtoffee · wordpress comments import and export7 нояб. 2023 г.

  • CVE-2022-46802
    39Наблюдать

    WordPress Product Reviews Import Export for WooCommerce Plugin <= 1.4.8 is vulnerable to CSV Injection

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    webtoffee · product reviews import export for woocommerce7 нояб. 2023 г.

  • CVE-2020-12074
    36Наблюдать

    The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    webtoffee · import export wordpress users22 апр. 2020 г.

  • CVE-2023-48284
    35Наблюдать

    WordPress Decorator – WooCommerce Email Customizer Plugin <= 1.2.7 is vulnerable to Cross Site Request Forgery (CSRF)

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    webtoffee · decorator30 нояб. 2023 г.

  • CVE-2018-11526
    33Наблюдать

    The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.

    ВысокаяCVSS 7,8Proof of conceptEPSS 5 %

    webtoffee · wordpress comments import and export19 июн. 2018 г.

  • CVE-2019-15092
    31Наблюдать

    The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, displ

    ВысокаяCVSS 7,3Proof of conceptEPSS 5 %

    webtoffee · import export wordpress users23 авг. 2019 г.

  • CVE-2024-0705
    31Наблюдать

    Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    webtoffee · stripe payment plugin for woocommerce19 янв. 2024 г.

  • CVE-2024-31254
    30Наблюдать

    WordPress WordPress Backup & Migration plugin <= 1.4.7 - Sensitive Data Exposure via Log File vulnerability

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    webtoffee · backup and migration10 апр. 2024 г.

  • CVE-2025-1970
    30Наблюдать

    Export and Import Users and Customers <= 2.6.2 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

    ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %

    webtoffee · import export wordpress users22 мар. 2025 г.

  • CVE-2025-1912
    30Наблюдать

    Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

    ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %

    webtoffee · product import export for woocommerce26 мар. 2025 г.

  • CVE-2023-6558
    28Наблюдать

    Export and Import Users and Customers <= 2.4.8 - Authenticated (Shop Manager+) Arbitrary File Upload

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    webtoffee · import export wordpress users11 янв. 2024 г.

  • CVE-2023-3459
    28Наблюдать

    Export and Import Users and Customers <= 2.4.1 - Missing Authorization to Authenticated (Shop Manager) Arbitrary User Password Change

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    webtoffee · import export wordpress users17 июл. 2023 г.

  • CVE-2025-1913
    28Наблюдать

    Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter

    ВысокаяCVSS 7,2Proof of conceptEPSS 1 %

    webtoffee · product import export for woocommerce26 мар. 2025 г.

  • CVE-2025-1971
    28Наблюдать

    Export and Import Users and Customers <= 2.6.2 - Authenticated (Admin+) PHP Object Injection via form_data Parameter

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    webtoffee · import export wordpress users22 мар. 2025 г.

  • CVE-2024-13921
    28Наблюдать

    Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    webtoffee · order export \& order import for woocommerce20 мар. 2025 г.

  • CVE-2023-51546
    28Наблюдать

    WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.2.1 - Privilege Escalation vulnerability

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    webtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labels17 мая 2024 г.

  • CVE-2024-30231
    28Наблюдать

    WordPress Product Import Export for WooCommerce plugin <= 2.4.1 - Arbitrary File Upload vulnerability

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    webtoffee · product import export for woocommerce26 мар. 2024 г.

  • CVE-2024-22135
    28Наблюдать

    WordPress Order Export & Order Import for WooCommerce Plugin <= 2.4.3 is vulnerable to Arbitrary File Upload

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    webtoffee · order export \& order import for woocommerce24 янв. 2024 г.

  • CVE-2024-22152
    28Наблюдать

    WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    webtoffee · product import export for woocommerce24 янв. 2024 г.

  • CVE-2025-1911
    26Наблюдать

    Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functi

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    webtoffee · product import export for woocommerce26 мар. 2025 г.

  • CVE-2025-1972
    26Наблюдать

    Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functi

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    webtoffee · import export wordpress users22 мар. 2025 г.

  • CVE-2024-13922
    26Наблюдать

    Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    webtoffee · order export \& order import for woocommerce20 мар. 2025 г.

  • CVE-2024-13923
    26Наблюдать

    Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    webtoffee · order export \& order import for woocommerce20 мар. 2025 г.

  • CVE-2023-7068
    26Наблюдать

    WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.3.0 - Missing Authorization to Order Export

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    webtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labels3 янв. 2024 г.