Pricing
Case studies
Login
Start trial
Comments Import & Export
WebToffee
Developer
2.5.0
Latest version
2,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
7 patched
2 Mitigation rules
Broken Access Control vulnerability
<= 2.4.9
20/03/2026
Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
<= 2.4.3
02/06/2025
Authenticated (Author+) Arbitrary File Read via Directory Traversal vulnerability
<= 2.3.7
10/10/2024
Cross Site Request Forgery (CSRF) vulnerability
<= 2.3.5
05/04/2024
CSV Injection
<= 2.3.1
06/02/2023
Cross-Site Request Forgery (CSRF) vulnerability
<= 2.1.10
11/03/2020
CSV Injection vulnerability
<= 2.3.1
22/06/2018