Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webtoffee

First CVE: Jun 19, 2018Active for: 8 yearsTotal CVEs: 43
34.2
VTI Score
Medium

Webtoffee develops a focused but widely deployed suite of WordPress and WooCommerce plugins centered on data import, export, backup, and order management, serving e-commerce platforms and administrative workflows across a large install base. Its vulnerability portfolio spans a modest count of disclosures concentrated in these core products and clusters around web-application and data-handling weakness classes: cross-site scripting in page generation, formula-injection risks in CSV export, unrestricted file uploads, unsafe deserialization, and path traversal in file operations—all characteristic of plugins that process user data and handle file I/O. A meaningful share of the vendor's vulnerabilities reach serious severity, and a notable portion acquire public exploit code, reflecting both the accessibility of plugin code and the plugin's appeal as a target for commerce-focused attack chains. Defenders should prioritize this vendor's updates for exposed WooCommerce storefronts and monitor the import/export and backup product lines specifically; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
43
Total CVEs
More Total CVEs than 98% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Webtoffee over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2018
8 years ago
Most Recent CVE
Jun 15, 2026
39 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (43 CVEs).

43 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-15092HIGH
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name colum
Aug 23, 20197.337NOYES
CVE-2018-11526HIGH
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
Jun 19, 20187.835NOYES
CVE-2024-0705HIGH
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient
Jan 19, 20247.533NOYES
CVE-2022-46802CRITICAL
Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee Product Reviews Import Export for WooCommerce.This issue affects Product Reviews Import Export
Nov 7, 20239.829NONO
CVE-2023-3162CRITICAL
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verificat
Aug 31, 20239.829NONO
CVE-2026-49056HIGH
Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions.
Jun 15, 20267.527NONO
CVE-2022-45370CRITICAL
Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from
Nov 7, 20239.826NONO
CVE-2023-48284HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WebToffee Decorator – WooCommerce Email Customizer allows Cross Site Request Forgery.This issue affects Decorator – WooCommerce E
Nov 30, 20238.825NONO
CVE-2025-1970HIGH
The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() func
Mar 22, 20257.623NONO
CVE-2024-30231HIGH
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a
Mar 26, 20247.223NONO
View all 43 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products43 CVEs
51%
42%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (4.7%)
Network41 (95.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low41 (95.3%)
High2 (4.7%)
Unknown0 (0.0%)
User Interaction
None34 (79.1%)
Unknown0 (0.0%)
Required9 (20.9%)
Privileges Required
Low8 (18.6%)
High20 (46.5%)
None15 (34.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (43 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.3% of CVEs· 95th percentile
ExploitDB
2 CVEs
4.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webtoffee.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webtoffee — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webtoffee's Products

View all 4 CNAs →

Top CWEs