Known Vulnerabilities for products from WebToffee

Listed below are 4 of the newest known vulnerabilities associated with the vendor "WebToffee".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-32441 Not Provided 2026-03-25 2026-03-26
CVE-2026-22480 Not Provided 2026-03-25 2026-03-26
CVE-2025-49287 Not Provided 2025-06-06 2026-04-01
CVE-2025-24657 Not Provided 2025-01-24 2026-04-01
CVE-2025-24651 Not Provided 2025-04-17 2026-04-01
CVE-2025-24644 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce P... Not Provided 2025-01-24 2026-04-01
CVE-2020-12074 The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administr... 8.8 - HIGH 2020-04-23 2021-07-21
CVE-2019-15092 The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the ... 7.3 - HIGH 2019-08-23 2020-08-24
CVE-2018-11526 The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection. 7.8 - HIGH 2018-06-19 2020-08-24

Known software with vulnerabilities from WebToffee

Type Vendor Product Version
ApplicationWebtoffeeImport Export Wordpress Users-
ApplicationWebtoffeeWordpress Comments Import And Export1.0.0