Confidence
Medium. Based on 20+ public sources; many review snippets were truncated mid-sentence.
Pricing
$0
Free versions
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Paid plugin licenses~$30–$69/yr
Sources & method
Analyzed 10/07/2026 - 12 sources - Widely used, but a long track record: ~50 CVEs, including 2025–26 SSRF, missing-authorization, and unauthenticated data exposure issues.
official x2review x5security x5
- CVE-2026-49056 — Unauthenticated Sensitive Data Exposure, Rated high; unauthenticated sensitive data exposure in a WebToffee plugin.
- CVE-2025-1912 — SSRF, Server-side request forgery in a WebToffee WooCommerce plugin.
- CVE-2025-64382 — Missing Authorization, Missing authorization check in a WebToffee plugin.
- CVE-2026-91020 — Gift Cards plugin, External control of assumed-immutable web parameter in Gift Cards for WooCommerce.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.