Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1856 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.14% | — | Integration FOR Epos NOW AND WoocommerceAI | 7/10/2026 | 7/10/2026 | The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails… | |
| Aplazada | Media (6.5) | 0.33% | — | Payplug FOR WoocommerceAI | 6/10/2026 | 6/10/2026 | Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | WPG Demos Woocommerce Simple AuctionsAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Wclovers Woocommerce Multivendor MarketplaceAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Midtrans WoocommerceAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Payplug FOR WoocommerceAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Storegrowth Smart Sales Booster FOR WoocommerceAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions. | |
| Aplazada | Alta (7.5) | 0.31% | — | Woocommerce LotteryAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in WooCommerce Lottery <= 2.2.9 versions. | |
| Aplazada | Crítica (9.9) | 0.74% | — | Woocommerce Designer PROAI | 6/10/2026 | 6/10/2026 | Subscriber Remote Code Execution (RCE) in WooCommerce Designer Pro <= 1.9.33 versions. | |
| Aplazada | Crítica (9.3) | 0.38% | — | Woocommerce AppointmentsAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions. | |
| Aplazada | Alta (7.1) | 0.19% | — | Villatheme Photo Reviews FOR WoocommerceAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30. | |
| Aplazada | Media (5.3) | 0.18% | — | KIT FOR WoocommerceAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Kit Kit (formerly ConvertKit) for WooCommerce convertkit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kit (formerly ConvertKit) for WooCommerce: from n/a through 2.2.0. | |
| Aplazada | Media (5.9) | 0.20% | — | Imaginate-solutions File Uploads Addon FOR WoocommerceAI | 5/10/2026 | 6/10/2026 | The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files. | |
| Aplazada | Media (5.3) | 0.18% | — | Razorpay FOR WoocommerceAI | 4/10/2026 | 6/10/2026 | The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders. | |
| Aplazada | Media (5.3) | 0.22% | — | Mailchimp FOR WoocommerceAI | 3/10/2026 | 6/10/2026 | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart. | |
| Aplazada | Media (4.3) | 0.16% | — | Helpdesk Support Ticket System FOR WoocommerceAI | 3/10/2026 | 6/10/2026 | The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level… | |
| Aplazada | Alta (8.1) | 0.34% | — | Photo Reviews FOR WoocommerceAI | 3/10/2026 | 6/10/2026 | The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta… | |
| Aplazada | Alta (7.2) | 0.24% | — | Cusrev Customer Reviews FOR WoocommerceAI | 2/10/2026 | 2/10/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (6.5) | 0.31% | — | DC Woocommerce Multi VendorAI | 2/10/2026 | 3/10/2026 | The Dc Woocommerce Multi Vendor plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter of the /multivendorx/v1/compliance/report-abuse REST endpoint in versions up to and including 5.0.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation… | |
| Aplazada | Media (5.3) | 0.26% | — | Webtoffee Gift Cards FOR WoocommerceAI | 2/10/2026 | 2/10/2026 | The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations… | |
| Aplazada | Alta (7.2) | 0.37% | — | Hide Shipping Method FOR WoocommerceAI | 1/10/2026 | 1/10/2026 | Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. | |
| Aplazada | Alta (7.5) | 0.30% | — | Photo Reviews FOR WoocommerceAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions. | |
| Aplazada | Alta (7.2) | 0.28% | — | PDF Invoices Packing Slips FOR WoocommerceAI | 1/10/2026 | 1/10/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.22% | — | WP Hosting AS PAY With Vipps FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.4. | |
| Aplazada | Media (5.4) | 0.10% | — | Razorpay Payment Links FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions. |