PricingCase studies Login Start trial
Plugin Icon

WordPress Comments Import & Export

WebToffee

Developer

2.4.8

Latest version

2,000

Installations

No date

Last updated

WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
    VulnerabilitiesSecurity Contributors

Vulnerability history

0 present
6 fixed
1 Mitigation rules
  • Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
    <= 2.4.3
    Jun 2, 2025
  • Authenticated (Author+) Arbitrary File Read via Directory Traversal vulnerability
    <= 2.3.7
    Oct 10, 2024
  • Cross Site Request Forgery (CSRF) vulnerability
    <= 2.3.5
    Apr 5, 2024
  • CSV Injection
    <= 2.3.1
    Feb 6, 2023
  • Cross-Site Request Forgery (CSRF) vulnerability
    <= 2.1.10
    Mar 11, 2020
  • CSV Injection vulnerability
    <= 2.3.1
    Jun 22, 2018

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Documentation
  • Service status
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory 1,085
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Vulnerability database
  • Whitepaper 2025 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
© 2025 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions
EU Flag