Woffice CRM <= 5.4.32 - Missing Authorization
medium
The Woffice CRM theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.4.32. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 5.4.32
- Fixed in:
- 5.4.33
- Disclosed:
- Jun 29, 2026
CVE-2026-27435 on NVD →
Woffice CRM [woffice] <= 5.4.30 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice allows Reflected XSS.This issue affects Woffice: from n/a through <= 5.4.30.
- Affected:
- up to 5.4.30
- Fix:
- No patched version reported
- Disclosed:
- Jan 8, 2026
CVE-2025-67918 on NVD →
Woffice <= 5.4.30 - Reflected Cross-Site Scripting
medium
The Woffice theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.4.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...
- CVSS:
- 6.1
- Affected:
- up to 5.4.30
- Fixed in:
- 5.4.31
- Disclosed:
- Jan 5, 2026
CVE-2025-67918 on NVD →
Woffice <= 5.4.21 - Authentication Bypass via Registration Role
critical
The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated attackers to register with an Administrator role if a custom login form is being us...
- CVSS:
- 9.8
- Affected:
- up to 5.4.21
- Fixed in:
- 5.4.22
- Disclosed:
- Apr 3, 2025
CVE-2025-2798 on NVD →
Woffice CRM [woffice] < 5.4.15
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice allows Authentication Bypass.This issue affects Woffice: from n/a through 5.4.14.
- Affected:
- up to 5.4.15
- Fixed in:
- 5.4.15
- Disclosed:
- Dec 16, 2024
CVE-2024-43234 on NVD →
Woffice <= 5.4.14 - Unauthenticated Privilege Escalation
critical
The Woffice CRM theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.4.14. This makes it possible for unauthenticated attackers to gain access to administrator accounts.
- CVSS:
- 9.8
- Affected:
- up to 5.4.14
- Fixed in:
- 5.4.15
- Disclosed:
- Dec 10, 2024
CVE-2024-43234 on NVD →
Woffice CRM [woffice] < 5.4.12
unknown
[en] Improper Privilege Management vulnerability in WofficeIO Woffice allows Privilege Escalation.This issue affects Woffice: from n/a through 5.4.10.
- Affected:
- up to 5.4.12
- Fixed in:
- 5.4.12
- Disclosed:
- Aug 13, 2024
CVE-2024-43153 on NVD →
Woffice <= 5.4.10 - Unauthenticated Privilege Escalation
critical
The Woffice CRM theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.10. This makes it possible for unauthenticated attackers to gain access to accounts with administrative level access.
- CVSS:
- 9.8
- Affected:
- up to 5.4.10
- Fixed in:
- 5.4.12
- Disclosed:
- Aug 7, 2024
CVE-2024-43153 on NVD →
Woffice CRM [woffice] < 5.4.9
unknown
[en] Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice allows Reflected XSS.This issue affects Woffice: from n/a through 5.4.8.
- Affected:
- up to 5.4.9
- Fixed in:
- 5.4.9
- Disclosed:
- Jul 4, 2024
CVE-2024-37472 on NVD →
Woffice <= 5.4.8 - Reflected Cross-Site Scripting
medium
The Woffice theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘[function_or_param]’ parameter in versions up to, and including, 5.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...
- CVSS:
- 6.1
- Affected:
- up to 5.4.8
- Fixed in:
- 5.4.9
- Disclosed:
- Jul 1, 2024
CVE-2024-37472 on NVD →
Woffice CRM <= 4.0.1 - Authorization Bypass
medium
The Woffice CRM theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the wofficeNotificationGet function in versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to view titles of notifications sent from user to user.
- CVSS:
- 5.3
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- Aug 26, 2021
Woffice CRM [woffice] < 4.0.2
unknown
The Woffice CRM theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the wofficeNotificationGet function in versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to view titles of notifications sent from user to user.
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- Aug 26, 2021
Woffice CRM [woffice] < 4.0.2
unknown
The theme lacks authentication checks before returning the titles of notifications between the site's users.
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
Woffice CRM [woffice] < 5.4.22
unknown
- Affected:
- up to 5.4.22
- Fixed in:
- 5.4.22
CVE-2025-2798 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database