Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1856 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.21% | — | Sysbasics Customize MY Account FOR WoocommerceAI | 18/6/2026 | 18/6/2026 | The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 4.3.6 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.4) | 0.19% | — | Sysbasics Customize MY Account FOR WoocommerceAI | 18/6/2026 | 18/6/2026 | The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode in versions up to, and including, 4.3.6. This is due to insufficient input sanitization and output escaping on user supplied attributes (min_height, min_width,… | |
| Aplazada | Media (4.9) | 0.47% | — | Algolplus Advanced Order Export FOR WoocommerceAI | 18/6/2026 | 18/6/2026 | The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_direction' parameter in all versions up to, and including, 4.0.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Cargo RD Cargo Shipping Location FOR WoocommerceAI | 17/6/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6. | |
| Aplazada | Crítica (9.8) | 0.48% | 💥 PoC | Registration Form FOR WoocommerceAI | 17/6/2026 | 17/6/2026 | Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Woocommerce Anti FraudAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Opmc Woocommerce DropshippingAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Woocommerce Product FiltersAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions. | |
| Aplazada | Alta (8.5) | 0.35% | — | Effress Woocommerce Frontend Manager UltimateAI | 17/6/2026 | 17/6/2026 | Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions. | |
| Aplazada | Alta (7.5) | 0.47% | — | Woocommerce Book PriceAI | 17/6/2026 | 17/6/2026 | Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions. | |
| Aplazada | Alta (7.5) | 0.47% | — | Wordpress Woocommerce ScraperAI | 17/6/2026 | 6/10/2026 | Unauthenticated Arbitrary File Download in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions. | |
| Aplazada | Crítica (10) | 0.43% | — | Wordpress Woocommerce ScraperAI | 17/6/2026 | 6/10/2026 | Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Woosolutions Woocommerce POSAI | 16/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions. | |
| Aplazada | Media (6.5) | 0.40% | — | Woocommerce Stripe Payment GatewayAI | 16/6/2026 | 17/6/2026 | The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment… | |
| Aplazada | Alta (7.5) | 0.42% | — | Signature Addon FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions. | |
| Aplazada | Alta (8.2) | 0.34% | — | Hippoo Mobile APP FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions. | |
| Aplazada | Alta (7.5) | 0.50% | — | WPC Product Options FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpcloud Woocommerce PDF Invoices Packing Slips Delivery Notes AND Shipping LabelsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Webtoffee WPC Product Bundles FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Montonio FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions. | |
| Aplazada | Alta (7.5) | 0.48% | — | Omnisend Email Marketing FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Redsys Woocommerce LightAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Shipment Tracker FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Wpdesk Woocommerce PDF Invoices Packing SlipsAI | 15/6/2026 | 17/6/2026 | Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wcproducttable Woocommerce Product Table LiteAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions. |