theme

Woffice Vulnerabilities

14 known security issues reported for the Woffice WordPress theme. Most recent disclosed Jun 29, 2026.

3 critical 4 medium

Running Woffice on your site? Check whether your installed version is affected.

Scan your site free

Woffice CRM <= 5.4.32 - Missing Authorization

medium

The Woffice CRM theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.4.32. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.4.32
Fixed in:
5.4.33
Disclosed:
Jun 29, 2026

CVE-2026-27435 on NVD →

Woffice CRM [woffice] <= 5.4.30 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice allows Reflected XSS.This issue affects Woffice: from n/a through <= 5.4.30.

Affected:
up to 5.4.30
Fix:
No patched version reported
Disclosed:
Jan 8, 2026

CVE-2025-67918 on NVD →

Woffice <= 5.4.30 - Reflected Cross-Site Scripting

medium

The Woffice theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.4.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

CVSS:
6.1
Affected:
up to 5.4.30
Fixed in:
5.4.31
Disclosed:
Jan 5, 2026

CVE-2025-67918 on NVD →

Woffice <= 5.4.21 - Authentication Bypass via Registration Role

critical

The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated attackers to register with an Administrator role if a custom login form is being us...

CVSS:
9.8
Affected:
up to 5.4.21
Fixed in:
5.4.22
Disclosed:
Apr 3, 2025

CVE-2025-2798 on NVD →

Woffice CRM [woffice] < 5.4.15

unknown

[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice allows Authentication Bypass.This issue affects Woffice: from n/a through 5.4.14.

Affected:
up to 5.4.15
Fixed in:
5.4.15
Disclosed:
Dec 16, 2024

CVE-2024-43234 on NVD →

Woffice <= 5.4.14 - Unauthenticated Privilege Escalation

critical

The Woffice CRM theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.4.14. This makes it possible for unauthenticated attackers to gain access to administrator accounts.

CVSS:
9.8
Affected:
up to 5.4.14
Fixed in:
5.4.15
Disclosed:
Dec 10, 2024

CVE-2024-43234 on NVD →

Woffice CRM [woffice] < 5.4.12

unknown

[en] Improper Privilege Management vulnerability in WofficeIO Woffice allows Privilege Escalation.This issue affects Woffice: from n/a through 5.4.10.

Affected:
up to 5.4.12
Fixed in:
5.4.12
Disclosed:
Aug 13, 2024

CVE-2024-43153 on NVD →

Woffice <= 5.4.10 - Unauthenticated Privilege Escalation

critical

The Woffice CRM theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.10. This makes it possible for unauthenticated attackers to gain access to accounts with administrative level access.

CVSS:
9.8
Affected:
up to 5.4.10
Fixed in:
5.4.12
Disclosed:
Aug 7, 2024

CVE-2024-43153 on NVD →

Woffice CRM [woffice] < 5.4.9

unknown

[en] Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice allows Reflected XSS.This issue affects Woffice: from n/a through 5.4.8.

Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
Jul 4, 2024

CVE-2024-37472 on NVD →

Woffice <= 5.4.8 - Reflected Cross-Site Scripting

medium

The Woffice theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘[function_or_param]’ parameter in versions up to, and including, 5.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...

CVSS:
6.1
Affected:
up to 5.4.8
Fixed in:
5.4.9
Disclosed:
Jul 1, 2024

CVE-2024-37472 on NVD →

Woffice CRM <= 4.0.1 - Authorization Bypass

medium

The Woffice CRM theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the wofficeNotificationGet function in versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to view titles of notifications sent from user to user.

CVSS:
5.3
Affected:
up to 4.0.1
Fixed in:
4.0.2
Disclosed:
Aug 26, 2021

Woffice CRM [woffice] < 4.0.2

unknown

The Woffice CRM theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the wofficeNotificationGet function in versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to view titles of notifications sent from user to user.

Affected:
up to 4.0.2
Fixed in:
4.0.2
Disclosed:
Aug 26, 2021

Woffice CRM [woffice] < 4.0.2

unknown

The theme lacks authentication checks before returning the titles of notifications between the site&#039;s users.

Affected:
up to 4.0.2
Fixed in:
4.0.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database