VendorsXtendifywofficeany version
Vulnerabilities

Xtendify Woffice any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2024-43234
WordPress Woffice theme <= 5.4.14 - Unauthenticated Account Takeover vulnerability
Published 2024-12-16 · Modified
9.8EPSS 0.007
CVE-2025-2798
Woffice <= 5.4.21 - Authentication Bypass via Registration Role
Published 2025-04-04 · Analyzed
9.8EPSS 0.007
CVE-2024-43153
WordPress Woffice theme <= 5.4.10 - Unauthenticated Privilege Escalation vulnerability
Published 2024-08-13 · Modified
9.8EPSS 0.006
CVE-2024-37470
WordPress Woffice Core plugin <= 5.4.8 - Unauthenticated Broken Access Control vulnerability
Published 2024-11-01 · Analyzed
9.8EPSS 0.005
CVE-2025-2780
Woffice Core <= 5.4.21 - Authenticated (Subscriber+) Arbitrary File Upload
Published 2025-04-04 · Analyzed
8.8EPSS 0.008
CVE-2025-7694
Woffice Core <= 5.4.26 - Authenticated (Contributor+) Arbitrary File Deletion
Published 2025-08-02 · Analyzed
7.5EPSS 0.009
CVE-2024-37472
WordPress Woffice theme <= 5.4.8 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-07-04 · Modified
7.1EPSS 0.003
CVE-2024-37471
WordPress Woffice Core plugin <= 5.4.8 - Site Wide Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-07-04 · Analyzed
7.1EPSS 0.003
CVE-2025-2797
Woffice Core <= 5.4.21 - Cross-Site Request Forgery to User Registration Approval
Published 2025-04-04 · Analyzed
5.4EPSS 0.001