📦 Woffice

by Xtendify

🔍 What is Woffice?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-43234

CRITICAL CVSS 9.8 Dec 16, 2024

This vulnerability allows unauthenticated attackers to bypass authentication mechanisms in the Woffice WordPress theme, potentially gaining administrative access to affected WordPress sites. All WordP...

CVE-2025-2780

HIGH CVSS 8.8 Apr 4, 2025

The Woffice Core plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access or higher to upload arbitrary files due to missing file type validation. This can...

CVE-2024-37470

HIGH CVSS 8.2 Nov 1, 2024

This vulnerability allows unauthenticated attackers to access functionality that should be restricted by proper authorization controls in the Woffice Core WordPress plugin. It affects all WordPress si...

CVE-2024-37471

HIGH CVSS 7.1 Jul 4, 2024

This CVE describes a reflected cross-site scripting (XSS) vulnerability in the Woffice Core WordPress plugin. Attackers can inject malicious scripts via crafted URLs that execute when victims visit th...

CVE-2025-7694

MEDIUM CVSS 6.8 Aug 2, 2025

The Woffice Core WordPress plugin allows authenticated attackers with Contributor-level access or higher to delete arbitrary server files due to insufficient path validation in the woffice_file_manage...