Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.29% | — | Wpclever WPC Product OptionsAI | 3/10/2026 | 6/10/2026 | The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.1) | 0.21% | — | Wpclever WPC Estimated Delivery DateAI | 3/10/2026 | 6/10/2026 | The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rule_data' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.1) | 0.31% | — | Wpclever WPC Smart Quick ViewAI | 3/10/2026 | 6/10/2026 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-redirect' parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (8.8) | 0.47% | — | Wpclever WPC Shop AS A CustomerAI | 1/10/2026 | 3/10/2026 | The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated… | |
| Aplazada | Media (5.3) | 0.21% | — | Wpclever WPC Smart CompareAI | 23/9/2026 | 23/9/2026 | The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description of password-protected products. | |
| Aplazada | Alta (7.2) | 0.24% | — | Wpclever WPC Product BundlesAI | 22/9/2026 | 22/9/2026 | The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and including, 8.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (7.5) | 0.75% | 💥 PoC | Cleverange AuthAI | 1/9/2026 | 3/9/2026 | An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component | |
| Aplazada | Media (5.5) | 0.71% | — | Cleverbrush FrameworkAI | 25/8/2026 | 28/9/2026 | A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Crítica (9.8) | 0.63% | — | Soclever Social Login Sharing Buttons With AnalyticsAI | 22/8/2026 | 26/8/2026 | The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators.… | |
| Aplazada | Media (6.5) | 0.37% | — | Wpclever WPC Admin ColumnsAI | 12/8/2026 | 26/8/2026 | The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read arbitrary user, post and term metadata, including data belonging to administrators. | |
| Aplazada | Alta (7.5) | 0.43% | — | Wpclever WPC Order TIPAI | 9/8/2026 | 26/8/2026 | The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensitive order data belonging to any customer of the store, such as billing names, order IDs and statuses, fee amounts and… | |
| Aplazada | Alta (7.5) | 0.37% | — | Wpclever WPC Name Your PriceAI | 6/8/2026 | 26/8/2026 | The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real… | |
| Aplazada | Media (4.3) | 0.25% | — | Cleverplugins Clever Mega Menu FOR Visual ComposerAI | 2/8/2026 | 26/8/2026 | The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public… | |
| Aplazada | Media (6.1) | 0.26% | — | Clevertap WEB SDKAI | 30/7/2026 | 1/10/2026 | CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that, when processed by renderCustomHtml, results in execution of arbitrary JavaScript… | |
| Aplazada | Media (6.4) | 0.33% | — | Wpclever WPC Badge ManagementAI | 29/7/2026 | 30/7/2026 | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (4.9) | 0.44% | — | Cleverplugins SEO BoosterAI | 16/7/2026 | 17/7/2026 | The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Media (4.9) | 0.44% | — | Cleverplugins SEO BoosterAI | 16/7/2026 | 16/7/2026 | The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Media (5.5) | 0.21% | — | Wpclever WPC Badge ManagementAI | 13/5/2026 | 7/10/2026 | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.33% | — | Wpclever WPC Smart MessagesAI | 28/4/2026 | 17/6/2026 | The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcsm_text_rotator` shortcode in all versions up to, and including, 4.2.8. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Aplazada | Media (4.3) | 0.25% | — | Wpclever WPC Smart WishlistAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WPClever WPC Smart Wishlist for WooCommerce woo-smart-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Smart Wishlist for WooCommerce: from n/a through <= 5.0.8. | |
| Aplazada | Media (4.3) | 0.27% | — | Wpclever WPC Product BundlesAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WPClever WPC Product Bundles for WooCommerce woo-product-bundle allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Product Bundles for WooCommerce: from n/a through <= 8.4.5. | |
| Analizada | Alta (8.3) | 0.53% | — | Clevertap WEB SDK | 27/2/2026 | 17/6/2026 | CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual Builder module. The origin validation in src/modules/visualBuilder/pageBuilder.js (lines 56-60) uses the includes() method to verify the originUrl contains "dashboard.clevertap.com",… | |
| Analizada | Alta (8.3) | 0.22% | — | Clevertap WEB SDK | 27/2/2026 | 17/6/2026 | CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent function in src/util/campaignRender/nativeDisplay.js performs insufficient origin validation using the includes() method, which can be bypassed by an attacker… | |
| Aplazada | Crítica (9.3) | 0.45% | — | Cleverreach WPAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp allows SQL Injection.This issue affects CleverReach® WP: from n/a through <= 1.5.21. | |
| Aplazada | Media (6.5) | 0.40% | — | Cleverplugins SEO BoosterAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in cleverplugins SEO Booster seo-booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEO Booster: from n/a through <= 6.1.8. |