Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1856 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.34% | — | Wpswings Wallet System FOR WoocommerceAI | 29/6/2026 | 29/6/2026 | Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Woocommerce Designer PROAI | 29/6/2026 | 1/7/2026 | Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions. | |
| Aplazada | Media (4.3) | 0.37% | — | Product Specifications FOR WoocommerceAI | 27/6/2026 | 29/6/2026 | The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, and deletion of data in versions up to and including 0.8.9. This is due to a missing capability check and missing nonce verification in the __invoke() methods of the AttributeGroupController and… | |
| Aplazada | Media (4.3) | 0.29% | — | Bopo Woocommerce Product Bundle BuilderAI | 26/6/2026 | 26/6/2026 | Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions. | |
| Aplazada | Media (4.3) | 0.14% | — | Flycart Abandoned Cart Lite FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Funnelkit Payment Gateway FOR Stripe WoocommerceAI | 26/6/2026 | 29/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | Omnisend Email Marketing FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Subscriptions FOR WoocommerceAI | 26/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpfactory Print Invoice AND Delivery Notes FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Woocart Payment Gateway Based Fees AND Discounts FOR WoocommerceAI | 26/6/2026 | 29/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Cusrev Customer Reviews FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Corvuspay Woocommerce Payment GatewayAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions. | |
| Aplazada | Crítica (9.9) | 0.48% | — | Booster FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Paymob FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Themeisle Ppom FOR WoocommerceAI | 25/6/2026 | 25/6/2026 | Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18. | |
| Aplazada | Alta (7.1) | 0.25% | — | Algolplus Advanced Order Export FOR WoocommerceAI | 25/6/2026 | 25/6/2026 | Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Wpexperts License Manager FOR WoocommerceAI | 25/6/2026 | 29/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Premmerce Wishlist FOR WoocommerceAI | 25/6/2026 | 25/6/2026 | Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions. | |
| Aplazada | Alta (8.3) | 0.32% | — | Saad Iqbal Apiexperts Square FOR WoocommerceAI | 25/6/2026 | 25/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3. | |
| Aplazada | Media (6.4) | 0.33% | — | Avalon23 Products Filter FOR WoocommerceAI | 24/6/2026 | 25/6/2026 | The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and including, 1.1.6. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes (notably 'title' and… | |
| Aplazada | Alta (7.5) | 0.43% | — | Shapedsmart Smart Post Show PROAIReal Testimonials PROAIProduct Slider FOR Woocommerce PROAI | 24/6/2026 | 25/6/2026 | Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for… | |
| Aplazada | Alta (7.1) | 0.25% | — | Ultimate Woocommerce Auction PROAI | 22/6/2026 | 22/6/2026 | The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Media (6.1) | 0.25% | — | Ultimate-woocommerce-auction-pro Ultimate Woocommerce Auction PROAI | 22/6/2026 | 22/6/2026 | The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Crítica (9.3) | 1.1% | — | WoocommerceAI | 20/6/2026 | 6/10/2026 | WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious… | |
| Aplazada | Media (4.9) | 0.59% | — | Woosa Marktplaats FOR WoocommerceAI | 19/6/2026 | 23/6/2026 | The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in versions up to and including 2.0.4. This is due to insufficient path sanitization in the render_logs_ui() function, which accepts a base64-encoded file name from the 'log_file' GET parameter and… |