PatchSiren

WofficeIO CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WofficeIO CVE published 2026-01-08

CVE-2025-67919

A CVE record for an Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core was published on 2026-01-08T10:15:50.840Z and last modified on 2026-09-30T23:10:00.237Z. The NVD entry is currently Deferred. Defenders responsible for Woffice Core installations should assess exposure and prioritize patching to prevent potential authorization bypasses. The vulnerability affects ve [truncated]

HIGH WofficeIO CVE published 2026-01-08

CVE-2025-67918

A Cross-site Scripting (XSS) vulnerability exists in Woffice, a WordPress theme, from version n/a through 5.4.30. This issue allows for Reflected XSS attacks. The CVE record was published on 2026-01-08T10:15:50.720Z and has not been modified since then. The NVD entry is currently Deferred. Defenders should assess exposure and consider remediation or compensating controls. The vulnerability arises from imp [truncated]