SecAlerts
w

webtoffee

Security Risk Profile

38
/100
low

Security Risk Score

Comprehensive risk assessment based on 62 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 19, 2018 to present

62
Total CVEs
25
Critical+High
0
Exploited
9
Unpatched

Threat Assessment

Avg CVSS
6.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
9
Critical/High
Risk Level
38/100
low
📈 2 in Last 30 Days

Severity Distribution

Critical
5
High
20
Medium
35
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
18

Age Distribution

Common Weaknesses (CWE)

1
XSS
11
2
Path Traversal
5
3
Malicious File Upload
4
4
CSRF
3
5
SSRF
3

Most Affected Products

1. WebToffee Import Export Wordpress Users Wordpress8
2. WebToffee Product Import Export For Woocommerce Wordpress6
3. WebToffee Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels Wordpress6
4. WebToffee Order Export \& Order Import For Woocommerce Wordpress5
5. WebToffee GDPR Cookie Compliance5

Recent Vulnerabilities

See more →
CVE-2026-18027
CVSS 6.5medium

WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.8 - Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' Parameter

Aug 22, 2026🔧 No Patch
CVE-2026-13389
CVSS 6.5medium

WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes

Aug 2, 2026🔧 No Patch
CVE-2026-48971
CVSS 4.3medium

WordPress Product Import Export for WooCommerce plugin <= 2.5.6 - Broken Access Control vulnerability

May 27, 2026
CVE-2026-45438
CVSS 7.5high

WordPress Smart Coupons for WooCommerce plugin < 2.3.0 - Broken Access Control vulnerability

May 25, 2026🔧 No Patch
CVE-2026-32441
CVSS 7.7high

WordPress Comments Import & Export plugin <= 2.4.9 - Broken Access Control vulnerability

Mar 25, 2026🔧 No Patch
CVE-2026-22480
CVSS 7.2high

WordPress Product Feed for WooCommerce plugin <= 2.3.3 - PHP Object Injection vulnerability

Mar 25, 2026🔧 No Patch
CVE-2025-67599
CVSS 4.3medium

WordPress WebToffee eCommerce Marketing Automation plugin <= 2.1.1 - Broken Access Control vulnerability

Dec 9, 2025🔧 No Patch
CVE-2025-66089
CVSS 4.3medium

WordPress Product Feed for WooCommerce plugin <= 2.3.1 - Broken Access Control vulnerability

Nov 21, 2025🔧 No Patch
CVE-2025-64382
CVSS 4.3medium

WordPress Order Export & Order Import for WooCommerce plugin <= 2.6.7 - Broken Access Control vulnerability

Nov 13, 2025🔧 No Patch
CVE-2025-64358
CVSS 4.3medium

WordPress Smart Coupons for WooCommerce plugin <= 2.2.3 - Broken Access Control vulnerability

Oct 31, 2025🔧 No Patch

Monitor webtoffee in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

webtoffee Security Vulnerabilities & Risk Score | 62 CVEs | SecAlerts - SecAlerts