Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1856 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.34%—Wpswings Wallet System FOR WoocommerceAI29/6/202629/6/2026
Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
AplazadaMedia (6.5)0.22%—Woocommerce Designer PROAI29/6/20261/7/2026
Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.
AplazadaMedia (4.3)0.37%—Product Specifications FOR WoocommerceAI27/6/202629/6/2026
The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, and deletion of data in versions up to and including 0.8.9. This is due to a missing capability check and missing nonce verification in the __invoke() methods of the AttributeGroupController and…
AplazadaMedia (4.3)0.29%—Bopo Woocommerce Product Bundle BuilderAI26/6/202626/6/2026
Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.
AplazadaMedia (4.3)0.14%—Flycart Abandoned Cart Lite FOR WoocommerceAI26/6/202626/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
AplazadaMedia (6.5)0.17%—Funnelkit Payment Gateway FOR Stripe WoocommerceAI26/6/202629/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions.
AplazadaMedia (5.4)0.29%—Omnisend Email Marketing FOR WoocommerceAI26/6/202626/6/2026
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
AplazadaAlta (7.5)0.35%—Subscriptions FOR WoocommerceAI26/6/202629/6/2026
Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.
AplazadaAlta (7.5)0.42%—Wpfactory Print Invoice AND Delivery Notes FOR WoocommerceAI26/6/202626/6/2026
Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.
AplazadaMedia (6.5)0.33%—Woocart Payment Gateway Based Fees AND Discounts FOR WoocommerceAI26/6/202629/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.
AplazadaAlta (7.1)0.25%—Cusrev Customer Reviews FOR WoocommerceAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.
AplazadaAlta (7.5)0.43%—Corvuspay Woocommerce Payment GatewayAI26/6/202626/6/2026
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
AplazadaCrítica (9.9)0.48%—Booster FOR WoocommerceAI26/6/202626/6/2026
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
AplazadaAlta (7.5)0.35%—Paymob FOR WoocommerceAI26/6/202626/6/2026
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
AplazadaMedia (6.5)0.33%—Themeisle Ppom FOR WoocommerceAI25/6/202625/6/2026
Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18.
AplazadaAlta (7.1)0.25%—Algolplus Advanced Order Export FOR WoocommerceAI25/6/202625/6/2026
Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.
AplazadaMedia (6.5)0.33%—Wpexperts License Manager FOR WoocommerceAI25/6/202629/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
AplazadaCrítica (9.3)0.40%—Premmerce Wishlist FOR WoocommerceAI25/6/202625/6/2026
Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.
AplazadaAlta (8.3)0.32%—Saad Iqbal Apiexperts Square FOR WoocommerceAI25/6/202625/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.
AplazadaMedia (6.4)0.33%—Avalon23 Products Filter FOR WoocommerceAI24/6/202625/6/2026
The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and including, 1.1.6. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes (notably 'title' and…
AplazadaAlta (7.5)0.43%—Shapedsmart Smart Post Show PROAIReal Testimonials PROAIProduct Slider FOR Woocommerce PROAI24/6/202625/6/2026
Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for…
AplazadaAlta (7.1)0.25%—Ultimate Woocommerce Auction PROAI22/6/202622/6/2026
The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaMedia (6.1)0.25%—Ultimate-woocommerce-auction-pro Ultimate Woocommerce Auction PROAI22/6/202622/6/2026
The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaCrítica (9.3)1.1%—WoocommerceAI20/6/20266/10/2026
WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious…
AplazadaMedia (4.9)0.59%—Woosa Marktplaats FOR WoocommerceAI19/6/202623/6/2026
The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in versions up to and including 2.0.4. This is due to insufficient path sanitization in the render_logs_ui() function, which accepts a base64-encoded file name from the 'log_file' GET parameter and…