Skip to main content

Vendor/product archive

xtendify / woffice CVEs

Beta · best-effort

9 CVEs tagged to xtendify / woffice3 Critical, 4 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2025-7694

Published Aug 2, 2025

The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the woffice_file_manager_delete() function in all versio…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2798

Published Apr 4, 2025

The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-2797

Published Apr 4, 2025

The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.4.21. This is due to missing or incorrect nonce validatio…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-2780

Published Apr 4, 2025

The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'saveFeaturedImage' function i…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-43234

Published Dec 16, 2024

Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice woffice allows Authentication Bypass.This issue affects Woffice: from n/a through <= 5.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-37470

Published Nov 1, 2024

Missing Authorization vulnerability in WofficeIO Woffice Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woffice Core: from n/a through 5.4…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43153

Published Aug 13, 2024

Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-37472

Published Jul 4, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37471

Published Jul 4, 2024

Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1