Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gdpr Cookie Consent MEDIUM 6.5
CVE-2024-8286

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make l…

Fix: 2.6.1+
Fix from $1,600 2025-05-15
Gdpr Cookie Consent MEDIUM 5.4
CVE-2024-8397

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visi…

Fix: 2.61+
Fix from $1,600 2025-05-15
Product Import Export For Woocommerce HIGH 7.6
CVE-2025-1912

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all …

Fix: 2.5.1+
Fix from $1,950 2025-03-26
Product Import Export For Woocommerce HIGH 7.2
CVE-2025-1913

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all version…

Fix: 2.5.1+
Fix from $1,950 2025-03-26
Product Import Export For Woocommerce MEDIUM 6.5
CVE-2025-1911

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insu…

Fix: 2.5.1+
Fix from $1,600 2025-03-26
Import Export Wordpress Users HIGH 7.2
CVE-2025-1971

The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via …

Fix: 2.6.3+
Fix from $1,950 2025-03-22
Import Export Wordpress Users MEDIUM 6.5
CVE-2025-1972

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t…

Fix: 2.6.3+
Fix from $1,600 2025-03-22
Import Export Wordpress Users HIGH 7.6
CVE-2025-1970

The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6…

Fix: 2.6.3+
Fix from $1,950 2025-03-22
Order Export \& Order Import For Woocommerce HIGH 7.2
CVE-2024-13921

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.…

Fix: 2.6.1+
Fix from $1,950 2025-03-20
Order Export \& Order Import For Woocommerce MEDIUM 6.5
CVE-2024-13922

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio…

Fix: 2.6.1+
Fix from $1,600 2025-03-20
Order Export \& Order Import For Woocommerce MEDIUM 6.5
CVE-2024-13923

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin…

Fix: 2.6.1+
Fix from $1,600 2025-03-20
Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels HIGH 7.2
CVE-2023-51546

Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege…

Fix: 4.3.0+
Fix from $1,950 2024-05-17
Backup And Migration HIGH 7.5
CVE-2024-31254

Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migrat…

Fix: 1.4.8+
Fix from $1,950 2024-04-10
Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels MEDIUM 5.3
CVE-2024-3216

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of da…

Fix: 4.4.3+
Fix from $1,600 2024-04-06
Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels MEDIUM 6.1
CVE-2024-22288

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Sli…

Fix: 4.4.1+
Fix from $1,600 2024-03-27
Product Import Export For Woocommerce HIGH 7.2
CVE-2024-30231

Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Ex…

Fix: after 2.4.1
Fix from $1,950 2024-03-26
Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels MEDIUM 6.1
CVE-2024-0957

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via…

Fix: 4.4.2+
Fix from $1,600 2024-03-22
Order Export \& Order Import For Woocommerce HIGH 7.2
CVE-2024-22135

Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Expor…

Fix: 2.4.4+
Fix from $1,950 2024-01-24
Product Import Export For Woocommerce HIGH 7.2
CVE-2024-22152

Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Ex…

Fix: 2.3.8+
Fix from $1,950 2024-01-24
Stripe Payment Plugin For Woocommerce HIGH 7.5
CVE-2024-0705

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and inclu…

Fix: 3.8.0+
Fix from $1,950 2024-01-19
Import Export Wordpress Users HIGH 7.2
CVE-2023-6558

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on th…

Fix: after 2.4.8
Fix from $1,950 2024-01-11
Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels MEDIUM 6.5
CVE-2023-7068

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due…

Fix: 4.3.1+
Fix from $1,600 2024-01-03
Decorator HIGH 8.8
CVE-2023-48284

Cross-Site Request Forgery (CSRF) vulnerability in WebToffee Decorator – WooCommerce Email Customizer allows Cross Site Request Forgery.This issue af…

Fix: after 1.2.7
Fix from $1,950 2023-11-30
Backup And Migration MEDIUM 5.4
CVE-2023-5738

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as l…

Fix: 1.4.4+
Fix from $1,600 2023-11-27
Wordpress Comments Import And Export CRITICAL 9.8
CVE-2022-45370

Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress …

Fix: after 2.3.1
Fix from $2,300 2023-11-07
Product Reviews Import Export For Woocommerce CRITICAL 9.8
CVE-2022-46802

Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee Product Reviews Import Export for WooCommerce.This issue affects…

Fix: after 1.4.8
Fix from $2,300 2023-11-07
Stripe Payment Plugin For Woocommerce CRITICAL 9.8
CVE-2023-3162

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This i…

Fix: after 3.7.7
Fix from $2,300 2023-08-31
Stripe Payment Plugin For Woocommerce MEDIUM 5.3
CVE-2023-4040

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o…

Fix: 3.8.0+
Fix from $1,600 2023-08-18
Import Export Wordpress Users HIGH 7.2
CVE-2023-3459

The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o…

Fix: after 2.4.1
Fix from $1,950 2023-07-18
Import Export Wordpress Users HIGH 8.8
CVE-2020-12074

The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.

Fix: 1.3.9+
Fix from $1,950 2020-04-23