Webtoffee develops a focused but widely deployed suite of WordPress and WooCommerce plugins centered on data import, export, backup, and order management, serving e-commerce platforms and administrative workflows across a large install base. Its vulnerability portfolio spans a modest count of disclosures concentrated in these core products and clusters around web-application and data-handling weakness classes: cross-site scripting in page generation, formula-injection risks in CSV export, unrestricted file uploads, unsafe deserialization, and path traversal in file operations—all characteristic of plugins that process user data and handle file I/O. A meaningful share of the vendor's vulnerabilities reach serious severity, and a notable portion acquire public exploit code, reflecting both the accessibility of plugin code and the plugin's appeal as a target for commerce-focused attack chains. Defenders should prioritize this vendor's updates for exposed WooCommerce storefronts and monitor the import/export and backup product lines specifically; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webtoffee over time
Signals from CVEs in this vendor scope (43 CVEs).
43 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15092HIGH The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name colum | Aug 23, 2019 | 7.3 | 37 | NO | YES |
CVE-2018-11526HIGH The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection. | Jun 19, 2018 | 7.8 | 35 | NO | YES |
CVE-2024-0705HIGH The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient | Jan 19, 2024 | 7.5 | 33 | NO | YES |
CVE-2022-46802CRITICAL Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee Product Reviews Import Export for WooCommerce.This issue affects Product Reviews Import Export | Nov 7, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-3162CRITICAL The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verificat | Aug 31, 2023 | 9.8 | 29 | NO | NO |
CVE-2026-49056HIGH Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions. | Jun 15, 2026 | 7.5 | 27 | NO | NO |
CVE-2022-45370CRITICAL Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from | Nov 7, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-48284HIGH Cross-Site Request Forgery (CSRF) vulnerability in WebToffee Decorator – WooCommerce Email Customizer allows Cross Site Request Forgery.This issue affects Decorator – WooCommerce E | Nov 30, 2023 | 8.8 | 25 | NO | NO |
CVE-2025-1970HIGH The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() func | Mar 22, 2025 | 7.6 | 23 | NO | NO |
CVE-2024-30231HIGH Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a | Mar 26, 2024 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (43 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webtoffee.
Media articles that mention a CVE ID that affects a product developed by Webtoffee — matched by CVE ID, not by vendor name.