Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2024-8286 The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make l… Gdpr Cookie Consent 2.6.1+ Fix from $1,6002025-05-15 MEDIUM 5.4 CVE-2024-8397 The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visi… Gdpr Cookie Consent 2.61+ Fix from $1,6002025-05-15 HIGH 7.6 CVE-2025-1912 The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all … Product Import Export For Woocommerce 2.5.1+ Fix from $1,9502025-03-26 HIGH 7.2 CVE-2025-1913 The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all version… Product Import Export For Woocommerce 2.5.1+ Fix from $1,9502025-03-26 MEDIUM 6.5 CVE-2025-1911 The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insu… Product Import Export For Woocommerce 2.5.1+ Fix from $1,6002025-03-26 HIGH 7.2 CVE-2025-1971 The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via … Import Export Wordpress Users 2.6.3+ Fix from $1,9502025-03-22 MEDIUM 6.5 CVE-2025-1972 The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t… Import Export Wordpress Users 2.6.3+ Fix from $1,6002025-03-22 HIGH 7.6 CVE-2025-1970 The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6… Import Export Wordpress Users 2.6.3+ Fix from $1,9502025-03-22 HIGH 7.2 CVE-2024-13921 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.… Order Export \& Order Import For Woocommerce 2.6.1+ Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-13922 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio… Order Export \& Order Import For Woocommerce 2.6.1+ Fix from $1,6002025-03-20 MEDIUM 6.5 CVE-2024-13923 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin… Order Export \& Order Import For Woocommerce 2.6.1+ Fix from $1,6002025-03-20 HIGH 7.2 CVE-2023-51546 Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege… Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels 4.3.0+ Fix from $1,9502024-05-17 HIGH 7.5 CVE-2024-31254 Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migrat… Backup And Migration 1.4.8+ Fix from $1,9502024-04-10 MEDIUM 5.3 CVE-2024-3216 The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of da… Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels 4.4.3+ Fix from $1,6002024-04-06 MEDIUM 6.1 CVE-2024-22288 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Sli… Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels 4.4.1+ Fix from $1,6002024-03-27 HIGH 7.2 CVE-2024-30231 Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Ex… Product Import Export For Woocommerce after 2.4.1 Fix from $1,9502024-03-26 MEDIUM 6.1 CVE-2024-0957 The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels 4.4.2+ Fix from $1,6002024-03-22 HIGH 7.2 CVE-2024-22135 Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Expor… Order Export \& Order Import For Woocommerce 2.4.4+ Fix from $1,9502024-01-24 HIGH 7.2 CVE-2024-22152 Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Ex… Product Import Export For Woocommerce 2.3.8+ Fix from $1,9502024-01-24 HIGH 7.5 CVE-2024-0705 The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and inclu… Stripe Payment Plugin For Woocommerce 3.8.0+ Fix from $1,9502024-01-19 HIGH 7.2 CVE-2023-6558 The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on th… Import Export Wordpress Users after 2.4.8 Fix from $1,9502024-01-11 MEDIUM 6.5 CVE-2023-7068 The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due… Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels 4.3.1+ Fix from $1,6002024-01-03 HIGH 8.8 CVE-2023-48284 Cross-Site Request Forgery (CSRF) vulnerability in WebToffee Decorator – WooCommerce Email Customizer allows Cross Site Request Forgery.This issue af… Decorator after 1.2.7 Fix from $1,9502023-11-30 MEDIUM 5.4 CVE-2023-5738 The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as l… Backup And Migration 1.4.4+ Fix from $1,6002023-11-27 CRITICAL 9.8 CVE-2022-45370 Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress … Wordpress Comments Import And Export after 2.3.1 Fix from $2,3002023-11-07 CRITICAL 9.8 CVE-2022-46802 Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee Product Reviews Import Export for WooCommerce.This issue affects… Product Reviews Import Export For Woocommerce after 1.4.8 Fix from $2,3002023-11-07 CRITICAL 9.8 CVE-2023-3162 The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This i… Stripe Payment Plugin For Woocommerce after 3.7.7 Fix from $2,3002023-08-31 MEDIUM 5.3 CVE-2023-4040 The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… Stripe Payment Plugin For Woocommerce 3.8.0+ Fix from $1,6002023-08-18 HIGH 7.2 CVE-2023-3459 The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… Import Export Wordpress Users after 2.4.1 Fix from $1,9502023-07-18 HIGH 8.8 CVE-2020-12074 The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV. Import Export Wordpress Users 1.3.9+ Fix from $1,9502020-04-23