Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

3237 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.45%—Webtoffee Extra Product Options Builder FOR WoocommerceAI16/8/202626/8/2026
The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product Options Builder for WooCommerce WordPress…
AplazadaAlta (8.8)0.52%—Cedcommerce Wholesale MarketAI15/8/202620/8/2026
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2 via the ced_wholesale_request_send AJAX action. The ced_wholesale_request_send_callback() handler only verifies a nonce (which is exposed to any authenticated user through wp_localize_script on the…
AplazadaMedia (5.9)0.29%—Epeken ALL Kurir FOR WoocommerceAI14/8/202631/8/2026
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration,…
AplazadaAlta (8.6)0.45%—Paymob FOR WoocommerceAI14/8/202626/8/2026
The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to…
AplazadaAlta (7.1)0.26%—Snstheme Samex Clean Minimal Shop Woocommerce Wordpress ThemeAISnstheme M ANH Fashion Woocommerce Wordpress ThemeAI13/8/202614/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress…
AplazadaMedia (5.3)0.31%—Revolut Gateway FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
AplazadaAlta (7.6)0.38%—Mailchimp FOR WoocommerceAI13/8/202614/8/2026
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
AplazadaAlta (7.1)0.25%—Multiparcels Shipping FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.
AplazadaAlta (7.1)0.25%—Local Delivery Drivers FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.
AplazadaAlta (7.5)0.35%—Storegrowth Smart Sales Booster FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.
AplazadaAlta (7.5)0.42%—Woocommerce AppointmentsAI13/8/202614/8/2026
Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
AplazadaAlta (7.5)0.35%—Smepay UPI Gateway FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
AplazadaAlta (7.1)0.25%—Welcart E-commerceAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
AplazadaCrítica (9.8)0.50%—Wpfactory Customer Email Verification FOR WoocommerceAI13/8/202626/8/2026
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered…
AplazadaMedia (5.3)0.16%—Paypal Payment Gateway FOR WoocommerceAI12/8/202626/8/2026
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the…
AplazadaMedia (5.3)0.16%—Welcart EcommerceAI12/8/202626/8/2026
The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from unpaid to settled purely from an order number and a status flag, with no signature, amount, or origin check. Because…
AplazadaMedia (6.5)0.34%—Wpswings Wallet System FOR WoocommerceAI12/8/202626/8/2026
The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero, and complete checkout without paying the…
AplazadaMedia (5.3)0.34%—Order Sync With Zendesk FOR WoocommerceAI12/8/202626/8/2026
The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer…
AplazadaCrítica (9.8)0.96%—Woocommerce SubscriptionsAI12/8/202626/8/2026
The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a gadget chain present in the bundled…
AplazadaCrítica (9.1)0.40%—Wallet FOR WoocommerceAI12/8/202626/8/2026
The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers to top up their wallet balance for less than its value.
AplazadaMedia (5.4)0.23%—Welcart E CommerceAI12/8/202626/8/2026
The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any visitor viewing the product page.
AnalizadaCrítica (9.1)88%⚠ Explotación activa💥 ExploitAdobe CommerceAdobe Commerce B2BAdobe Magento11/8/202625/9/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
AnalizadaAlta (7.5)0.83%—Adobe Commerce B2BAdobe CommerceAdobe Magento11/8/202625/9/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
AnalizadaAlta (8.3)0.46%—Adobe CommerceAdobe MagentoAdobe Commerce B2B11/8/202625/9/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, causing a limited disruption to availability. Exploitation of this…
AnalizadaAlta (8.7)0.33%—Adobe CommerceAdobe MagentoAdobe Commerce B2B11/8/202625/9/2026
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially…