CVE-2025-67918

WordPress Woffice theme <= 5.4.30 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice allows Reflected XSS.This issue affects Woffice: from n/a through <= 5.4.30.


We have discovered 356 live websites that are affected by CVE-2025-67918.

Run a Free Instant Scan




Affected Software

Product  Woffice
Category Wordpress Themes
Vulnerable Domains356 live websites (100% of Woffice install base)
Vulnerable Versions
  • from 0 through 5.4.30
Vulnerable Versions Count30 versions ( 91% of all versions)



Details

  • Published - Jan 8, 2026
  • Updated - Jan 20, 2026

Credits

  • Rafie Muhammad (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2025-67918
United States109 websites



France38 websites
Germany29 websites
Netherlands26 websites
Portugal22 websites
Australia19 websites
Spain16 websites
GB14 websites
Italy11 websites
Brazil9 websites

Website Distribution by TLD

Number of websites using CVE-2025-67918
.com118 websites
.org31 websites
.fr16 websites
.com.au16 websites
.de16 websites
.net13 websites
.nl13 websites
.eu10 websites
.es9 websites
.ru5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-67918

Top websites that are affected by CVE-2025-67918. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com Italy***,***
********.**********.com GB***,***
*****.*******.com France***,***
***************.de Germany***,***
*******.pt Portugal***,***
********.org United States***,***
**.**************.pt Portugal*,***,***
**********.com United States*,***,***
*****.***.br Brazil*,***,***
****.*********.it Italy*,***,***
See full domain list

FAQ

A total of 356 websites have been identified as vulnerable to CVE-2025-67918, based on global website indexing conducted by WebTechSurvey.
The Woffice is affected by the CVE-2025-67918 vulnerability.
Woffice versions up to and including 5.4.30 are vulnerable to CVE-2025-67918.