Vulnerabilities in webtoffee

53 results
CVE-2026-45438HIGHWordPress Smart Coupons for WooCommerce plugin < 2.3.0 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-32441HIGHWordPress Comments Import & Export plugin <= 2.4.9 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2025-49287MEDIUMWordPress Product Feed for WooCommerce plugin <= 2.2.8 - Broken Access Control VulnerabilityEPSS 0.3%CVE-2024-34751MEDIUMWordPress Order Export & Order Import for WooCommerce plugin <= 2.4.9 - PHP Object Injection vulnerabilityEPSS 0.2%CVE-2025-3919MEDIUMWordPress Comments Import & Export <= 2.4.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site ScriptingEPSS 0.2%CVE-2026-48971MEDIUMWordPress Product Import Export for WooCommerce plugin <= 2.5.6 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2024-31235MEDIUMWordPress Comments Import & Export plugin <= 2.3.5 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2025-64358MEDIUMWordPress Smart Coupons for WooCommerce plugin <= 2.2.3 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-66112MEDIUMWordPress Accessibility Toolkit by WebYes plugin <= 2.0.4 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-66089MEDIUMWordPress Product Feed for WooCommerce plugin <= 2.3.1 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-64382MEDIUMWordPress Order Export & Order Import for WooCommerce plugin <= 2.6.7 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-67599MEDIUMWordPress WebToffee eCommerce Marketing Automation plugin <= 2.1.1 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-12113MEDIUMAlt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images <= 1.8.3 - Missing Authorization to Authenticated (Subscriber+) API Key DeletionEPSS 0.2%