W
Vendor security profile
webtoffee
Product portfolio, patch evidence and exploitation signals in a single security scorecard
The data is combined from the CVE Program, NVD, CISA KEV and vendor security advisories.
Total CVEs4
Critical0
CISA KEV0
Public exploit0
Patch rate%0
Avg. CVSS6.7
12-month vulnerability rate
0
0
0
0
0
0
0
0
0
1
1
2
CVE KEV
CVE severity distribution
4toplam CVE
High2 (50%)
Medium2 (50%)
Patch and exploitation view
%0
Verified patch
%0
CISA KEV
%0
Public exploit
0Patch available
0Partial
0Workaround
0Vendor: no patch
4Unknown
Latest vulnerabilities
7.5
CVE-2026-93746
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 5.0.2 - Insecure Direct Object Reference to Unauthenticated Unauthorized Order Document Access via 'email' Parameter
W
Patch status unknownEPSS %1
5.3
CVE-2026-94375
Order Export & Order Import for WooCommerce <= 2.7.8 - Unauthenticated Sensitive File Exposure via Missing Directory Guard Re-verification in get_file_path()
W
Patch status unknownEPSS %0
7.5
CVE-2026-97197
WordPress WordPress Backup & Migration plugin <= 1.6.0 - Broken Access Control vulnerability
W
Patch status unknownEPSS %0
6.5
CVE-2026-18027
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.8 - Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' Parameter
W
Patch status unknownEPSS %1