Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1856 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.38% | — | Realmag777 FOX Woocommerce Currency SwitcherAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Blind SQL Injection.This issue affects FOX: from n/a through <= 1.4.5. | |
| Aplazada | Crítica (9.1) | 0.24% | — | Order Notification FOR WoocommerceAI | 1/4/2026 | 7/10/2026 | The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers. | |
| Aplazada | Media (6.5) | 0.27% | — | Woocommerce WoopaymentsAI | 31/3/2026 | 17/6/2026 | The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_upe_appearance_ajax' function in all versions up to, and including, 10.5.1. This makes it possible for unauthenticated attackers to update plugin… | |
| Aplazada | Alta (7.1) | 0.25% | — | Villatheme Abandoned Cart Recovery FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Stored XSS.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.10. | |
| Aplazada | Alta (8.6) | 0.53% | — | Vanquish Woocommerce-support-ticket-systemAI | 25/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerce-support-ticket-system allows Path Traversal.This issue affects WooCommerce Support Ticket System: from n/a through < 18.5. | |
| Aplazada | Alta (7.7) | 0.39% | — | Webtoffee Comments Import AND Export WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comments Import & Export: from n/a through <= 2.4.9. | |
| Aplazada | Alta (8.2) | 0.38% | — | Devteam Products-rearrange-woocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Rearrange for WooCommerce: from n/a through <= 1.2.2. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Devteam Product Rearrange FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Blind SQL Injection.This issue affects Product Rearrange for WooCommerce: from n/a through <= 1.2.2. | |
| Aplazada | Alta (8.8) | 0.52% | — | Sbthemes Woocommerce Infinite ScrollAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in sbthemes WooCommerce Infinite Scroll sb-woocommerce-infinite-scroll allows Object Injection.This issue affects WooCommerce Infinite Scroll: from n/a through <= 1.6.2. | |
| Aplazada | Media (6.5) | 0.33% | — | Viabill WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in ViaBill for WooCommerce ViaBill – WooCommerce viabill-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ViaBill – WooCommerce: from n/a through <= 1.1.53. | |
| Aplazada | Media (6.5) | 0.34% | — | Pickplugins Product Slider FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Slider for WooCommerce: from n/a through <= 1.13.61. | |
| Aplazada | Alta (7.5) | 0.43% | — | Snowray Software File Uploader FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader for WooCommerce: from n/a through <= 1.0.4. | |
| Aplazada | Alta (7.5) | 0.26% | — | Coderpress Commerce Coinbase FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in CoderPress Commerce Coinbase For WooCommerce commerce-coinbase-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Commerce Coinbase For WooCommerce: from n/a through <= 1.6.6. | |
| Aplazada | Media (6.8) | 0.35% | — | Add-ons.org Products-file-upload-for-woocommerceAI | 25/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Product File Upload for WooCommerce products-file-upload-for-woocommerce allows Path Traversal.This issue affects Product File Upload for WooCommerce: from n/a through <= 2.2.4. | |
| Aplazada | Alta (7.5) | 0.33% | — | Tychesoftwares Woocommerce Delivery NotesAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.9.0. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Wpfactory Advanced Woocommerce Product Sales ReportingAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Blind SQL Injection.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <=… | |
| Aplazada | Alta (7.5) | 0.46% | — | Wpswings Subscriptions FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce allows Input Data Manipulation.This issue affects Subscriptions for WooCommerce: from n/a through <= 1.8.10. | |
| Aplazada | Alta (7.5) | 0.37% | — | Wpfactory Helpdesk Support Ticket System FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.2. | |
| Aplazada | Media (6.5) | 0.30% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.0. | |
| Aplazada | Alta (7.2) | 0.50% | — | Webtoffee Product Feed FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Object Injection.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.3. | |
| Aplazada | Media (6.5) | 0.48% | — | WBW Product Filter FOR WoocommerceAI | 24/3/2026 | 17/6/2026 | The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check in all versions up to, and including, 3.1.2. This is due to the plugin's MVC framework dynamically registering unauthenticated AJAX handlers via `wp_ajax_nopriv_` hooks without… | |
| Aplazada | Crítica (9.8) | 0.99% | 💥 PoC | Woocommerce Custom Product Addons PROAI | 24/3/2026 | 17/6/2026 | The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_custom_formula() function within includes/process/price.php. This is due to insufficient sanitization and validation of… | |
| Aplazada | Alta (7.5) | 0.43% | — | Multidots Fraud Prevention FOR WoocommerceAI | 19/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fraud Prevention For Woocommerce: from n/a through <= 2.3.3. | |
| Aplazada | Crítica (9.8) | 1.8% | 💥 Exploit | Rymera WEB CO PTY LTD Woocommerce Wholesale Lead CaptureAI | 19/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1. | |
| Aplazada | Crítica (9) | 1.6% | 💥 PoC | Rymera WEB CO PTY LTD Woocommerce Wholesale Lead CaptureAI | 19/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1. |