Byconsole develops point-of-sale and restaurant management applications such as WoodT Lite and its pickup, delivery, and dine-in ordering systems, with observed vulnerabilities centered on application-layer input handling and authorization controls including cross-site scripting, sensitive information disclosure in error messages, and missing authorization checks. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Byconsole over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47179HIGH Missing Authorization vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff | Jan 2, 2025 | 8.8 | 26 | NO | NO |
CVE-2023-0894MEDIUM The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to | May 8, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-45006MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ByConsole WooODT Lite – WooCommerce Order Delivery or Pickup with Date Time Location plugin <= 2.4.6 versions. | Oct 17, 2023 | 6.1 | 17 | NO | NO |
CVE-2024-13540MEDIUM The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.5.1. This | Feb 18, 2025 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Byconsole.
Media articles that mention a CVE ID that affects a product developed by Byconsole — matched by CVE ID, not by vendor name.