Filter
-Infinity
0

WebToffee GDPR Cookie ComplianceGDPR Cookie Compliance <= 4.15.6 - Authenticated (Admin+) Stored Cross-Site Scripting

First published (updated )

WebToffee Wishlist for WooCommerceWordPress Wishlist for WooCommerce plugin <=2.1.2 - Cross Site Scripting (XSS) vulnerability

EPSS
0.04%
First published (updated )

WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping LabelsWordPress WooCommerce PDF Invoices plugin <= 4.7.1 - Stored Cross Site Scripting (XSS) vulnerability

EPSS
0.04%
First published (updated )

Webtoffee Backup And MigrationWordPress Backup & Migration plugin <= 1.4.1 - Broken Access Control vulnerability

First published (updated )

Webtoffee Backup And MigrationWordPress WordPress Backup & Migration plugin <= 1.4.0 - Broken Access Control vulnerability

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Webtoffee Backup And MigrationWordPress WordPress Backup & Migration plugin <= 1.4.3 - Broken Access Control vulnerability

First published (updated )

WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping LabelsWordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.2.1 - Privilege Escalation vulnerability

7.2
First published (updated )

Webtoffee WordPress Comments Import And ExportWordPress Comments Import & Export plugin <= 2.3.5 - Cross Site Request Forgery (CSRF) vulnerability

EPSS
0.04%
First published (updated )

Webtoffee Backup And MigrationWordPress WordPress Backup & Migration plugin <= 1.4.7 - Sensitive Data Exposure via Log File vulnerability

3.7
EPSS
0.04%
First published (updated )

WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping LabelsThe WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress…

EPSS
0.04%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping LabelsWordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.4.0 - Reflected Cross Site Scripting (XSS) vulnerability

7.1
EPSS
0.04%
First published (updated )

WebToffee Product Import Export for WooCommerceWordPress Product Import Export for WooCommerce plugin <= 2.4.1 - Arbitrary File Upload vulnerability

EPSS
0.04%
First published (updated )

WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping LabelsXSS

First published (updated )

WebToffee Order Export & Order Import for WooCommerceWordPress Order Export & Order Import for WooCommerce Plugin <= 2.4.3 is vulnerable to Arbitrary File Upload

EPSS
0.05%
First published (updated )

WebToffee Product Import Export for WooCommerceWordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload

EPSS
0.05%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Payment Plugins for Stripe WooCommerceSQL Injection

EPSS
0.08%
First published (updated )

WebToffee Import Export WordPress UsersMalicious File Upload

7.2
EPSS
0.14%
First published (updated )

WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping LabelsThe WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress…

EPSS
0.05%
First published (updated )

Webtoffee DecoratorWordPress Decorator – WooCommerce Email Customizer Plugin <= 1.2.7 is vulnerable to Cross Site Request Forgery (CSRF)

8.8
First published (updated )

Webtoffee Backup And MigrationWordPress Backup & Migration < 1.4.5 - Subscriber+ Stored XSS

EPSS
0.04%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Webtoffee Backup And MigrationWordPress Backup & Migration < 1.4.4 - Subscriber+ Plugin Settings Update

EPSS
0.04%
First published (updated )

Webtoffee WordPress Comments Import And ExportWordPress WordPress Comments Import & Export Plugin <= 2.3.1 is vulnerable to CSV Injection

First published (updated )

Webtoffee Product Reviews Import Export For WoocommerceWordPress Product Reviews Import Export for WooCommerce Plugin <= 1.4.8 is vulnerable to CSV Injection

First published (updated )

Payment Plugins for Stripe WooCommerceThe Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypas…

First published (updated )

Payment Plugins for Stripe WooCommerceThe Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modific…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

WebToffee Import Export WordPress UsersThe Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modific…

7.2
First published (updated )

WebToffee Import Export WordPress UsersThe users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscr…

8.8
First published (updated )

WebToffee Import Export WordPress UsersThe webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress all…

7.3
First published (updated )

Webtoffee WordPress Comments Import And ExportThe plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to C…

7.8
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203