İçeriğe atla
Noroxi

WebToffee kayıtları

webtoffee üreticisine ait 40 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%40
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

40 kayıt
  • CVE-2023-3162
    39İzleyin

    Stripe Payment Plugin for WooCommerce <= 3.7.7 - Authentication Bypass

    KritikCVSS 9,8İstismar yokEPSS %1

    webtoffee · stripe payment plugin for woocommerce31 Ağu 2023

  • CVE-2022-45370
    39İzleyin

    WordPress WordPress Comments Import & Export Plugin <= 2.3.1 is vulnerable to CSV Injection

    KritikCVSS 9,8İstismar yokEPSS %1

    webtoffee · wordpress comments import and export7 Kas 2023

  • CVE-2022-46802
    39İzleyin

    WordPress Product Reviews Import Export for WooCommerce Plugin <= 1.4.8 is vulnerable to CSV Injection

    KritikCVSS 9,8İstismar yokEPSS %1

    webtoffee · product reviews import export for woocommerce7 Kas 2023

  • CVE-2020-12074
    36İzleyin

    The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts

    YüksekCVSS 8,8İstismar yokEPSS %2

    webtoffee · import export wordpress users22 Nis 2020

  • CVE-2023-48284
    35İzleyin

    WordPress Decorator – WooCommerce Email Customizer Plugin <= 1.2.7 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    webtoffee · decorator30 Kas 2023

  • CVE-2018-11526
    33İzleyin

    The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.

    YüksekCVSS 7,8Kavram kanıtıEPSS %5

    webtoffee · wordpress comments import and export19 Haz 2018

  • CVE-2019-15092
    31İzleyin

    The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, displ

    YüksekCVSS 7,3Kavram kanıtıEPSS %5

    webtoffee · import export wordpress users23 Ağu 2019

  • CVE-2024-0705
    31İzleyin

    Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    webtoffee · stripe payment plugin for woocommerce19 Oca 2024

  • CVE-2024-31254
    30İzleyin

    WordPress WordPress Backup & Migration plugin <= 1.4.7 - Sensitive Data Exposure via Log File vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %0

    webtoffee · backup and migration10 Nis 2024

  • CVE-2025-1970
    30İzleyin

    Export and Import Users and Customers <= 2.6.2 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

    YüksekCVSS 7,6İstismar yokEPSS %0

    webtoffee · import export wordpress users22 Mar 2025

  • CVE-2025-1912
    30İzleyin

    Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

    YüksekCVSS 7,6İstismar yokEPSS %0

    webtoffee · product import export for woocommerce26 Mar 2025

  • CVE-2023-6558
    28İzleyin

    Export and Import Users and Customers <= 2.4.8 - Authenticated (Shop Manager+) Arbitrary File Upload

    YüksekCVSS 7,2İstismar yokEPSS %1

    webtoffee · import export wordpress users11 Oca 2024

  • CVE-2023-3459
    28İzleyin

    Export and Import Users and Customers <= 2.4.1 - Missing Authorization to Authenticated (Shop Manager) Arbitrary User Password Change

    YüksekCVSS 7,2İstismar yokEPSS %1

    webtoffee · import export wordpress users17 Tem 2023

  • CVE-2025-1913
    28İzleyin

    Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter

    YüksekCVSS 7,2Kavram kanıtıEPSS %1

    webtoffee · product import export for woocommerce26 Mar 2025

  • CVE-2025-1971
    28İzleyin

    Export and Import Users and Customers <= 2.6.2 - Authenticated (Admin+) PHP Object Injection via form_data Parameter

    YüksekCVSS 7,2İstismar yokEPSS %1

    webtoffee · import export wordpress users22 Mar 2025

  • CVE-2024-13921
    28İzleyin

    Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter

    YüksekCVSS 7,2İstismar yokEPSS %1

    webtoffee · order export \& order import for woocommerce20 Mar 2025

  • CVE-2023-51546
    28İzleyin

    WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.2.1 - Privilege Escalation vulnerability

    YüksekCVSS 7,2İstismar yokEPSS %1

    webtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labels17 May 2024

  • CVE-2024-30231
    28İzleyin

    WordPress Product Import Export for WooCommerce plugin <= 2.4.1 - Arbitrary File Upload vulnerability

    YüksekCVSS 7,2İstismar yokEPSS %1

    webtoffee · product import export for woocommerce26 Mar 2024

  • CVE-2024-22135
    28İzleyin

    WordPress Order Export & Order Import for WooCommerce Plugin <= 2.4.3 is vulnerable to Arbitrary File Upload

    YüksekCVSS 7,2İstismar yokEPSS %1

    webtoffee · order export \& order import for woocommerce24 Oca 2024

  • CVE-2024-22152
    28İzleyin

    WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload

    YüksekCVSS 7,2İstismar yokEPSS %1

    webtoffee · product import export for woocommerce24 Oca 2024

  • CVE-2025-1911
    26İzleyin

    Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functi

    OrtaCVSS 6,5İstismar yokEPSS %0

    webtoffee · product import export for woocommerce26 Mar 2025

  • CVE-2025-1972
    26İzleyin

    Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functi

    OrtaCVSS 6,5İstismar yokEPSS %0

    webtoffee · import export wordpress users22 Mar 2025

  • CVE-2024-13922
    26İzleyin

    Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page

    OrtaCVSS 6,5İstismar yokEPSS %0

    webtoffee · order export \& order import for woocommerce20 Mar 2025

  • CVE-2024-13923
    26İzleyin

    Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function

    OrtaCVSS 6,5İstismar yokEPSS %0

    webtoffee · order export \& order import for woocommerce20 Mar 2025

  • CVE-2023-7068
    26İzleyin

    WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.3.0 - Missing Authorization to Order Export

    OrtaCVSS 6,5İstismar yokEPSS %0

    webtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labels3 Oca 2024