Webtoffee
webtoffee
37 CVEs • 10 products
Products (10)
Click to collapseToggle
Products (10)
Click to collapse
CVEs (37)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets t...Show more |
The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs v...Show more |
1Webtoffee 1Product Import Export For Woocommerce Dec 5, 2025 Mar 26, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.0 via deserialization of untrusted input fr...Show more |
1Webtoffee 1Product Import Export For Woocommerce Jul 9, 2025 Mar 26, 2025 N/A· v4 7.6 HIGH· v3 N/A· v2 The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the validate_file() Function....Show more |
1Webtoffee 1Product Import Export For Woocommerce Jul 9, 2025 Mar 26, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all v...Show more |
1Webtoffee 1Product Import Export For Woocommerce Jul 9, 2025 Mar 26, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.0 via the download_file() function. This mak...Show more |
1Webtoffee 1Import Export Wordpress Users Jul 9, 2025 Mar 22, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attack...Show more |
1Webtoffee 1Import Export Wordpress Users Jul 9, 2025 Mar 22, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6....Show more |
1Webtoffee 1Import Export Wordpress Users Jul 9, 2025 Mar 22, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'form_data' parameter. This...Show more |
1Webtoffee 1Import Export Wordpress Users Jul 9, 2025 Mar 22, 2025 N/A· v4 7.6 HIGH· v3 N/A· v2 The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() function. This makes it possible for authent...Show more |
1Webtoffee 1Order Export & Order Import For Woocommerce Mar 26, 2025 Mar 20, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function. This makes it possible for a...Show more |
1Webtoffee 1Order Export & Order Import For Woocommerce Mar 26, 2025 Mar 20, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including...Show more |
1Webtoffee 1Order Export & Order Import For Woocommerce Mar 26, 2025 Mar 20, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the 'form_data' parameter...Show more |
1Webtoffee 1Order Export & Order Import For Woocommerce Mar 27, 2025 Mar 20, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it possible for authentic...Show more |
1Webtoffee 1Woocommerce Pdf Invoices, Packing Slips, Delivery Notes And Shipping Labels Apr 23, 2026 Jan 24, 2025 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels print-invoices-packing-slip-labe...Show more |
1Webtoffee 1Woocommerce Pdf Invoices, Packing Slips, Delivery Notes And Shipping Labels Feb 11, 2025 May 17, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips,...Show more |
Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7. |
1Webtoffee 1Woocommerce Pdf Invoices, Packing Slips, Delivery Notes And Shipping Labels Apr 8, 2026 Apr 6, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wt_pklist_reset_settings()...Show more |
1Webtoffee 1Woocommerce Pdf Invoices, Packing Slips, Delivery Notes And Shipping Labels Apr 28, 2026 Mar 27, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Reflected XSS.This issue...Show more |
1Webtoffee 1Product Import Export For Woocommerce Apr 28, 2026 Mar 26, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.4.1. |