Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1856 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.26% | — | Addonify Floating Cart FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Addonify Addonify Floating Cart For WooCommerce addonify-floating-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify Floating Cart For WooCommerce: from n/a through <= 1.2.17. | |
| Aplazada | Media (6.5) | 0.26% | — | Addonify - Woocommerce WishlistAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Addonify Addonify – WooCommerce Wishlist addonify-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify – WooCommerce Wishlist: from n/a through <= 2.0.15. | |
| Aplazada | Media (6.5) | 0.34% | — | Addonify Compare Products FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Addonify Addonify – Compare Products For WooCommerce addonify-compare-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify – Compare Products For WooCommerce: from n/a through <= 1.1.17. | |
| Aplazada | Alta (7.3) | 0.34% | — | Soporteblue Bluex FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in soporteblue Plugin BlueX for WooCommerce bluex-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Plugin BlueX for WooCommerce: from n/a through <= 3.1.6. | |
| Aplazada | Media (6.5) | 0.29% | — | Knitpay UPI QR Code Payment Gateway FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in knitpay UPI QR Code Payment Gateway for WooCommerce upi-qr-code-payment-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UPI QR Code Payment Gateway for WooCommerce: from n/a through <= 1.5.1. | |
| Aplazada | Alta (7.5) | 0.35% | — | Product Table AND List Builder FOR Woocommerce LiteAI | 19/2/2026 | 17/6/2026 | The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 4.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (5.3) | 0.22% | — | Alma-gateway-for-woocommerceAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Alma Alma alma-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Alma: from n/a through <= 5.16.1. | |
| Aplazada | Media (5.3) | 0.22% | — | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Ultimate Gift Cards For WooCommerce woo-gift-cards-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Gift Cards For WooCommerce: from n/a through <= 3.2.4. | |
| Aplazada | Alta (7.2) | 0.49% | — | Yithemes Yith Woocommerce CompareAI | 19/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Object Injection.This issue affects YITH WooCommerce Compare: from n/a through <= 3.6.0. | |
| Aplazada | Media (4.3) | 0.13% | — | Whatsiplus Scheduled Notification FOR WoocommerceAI | 19/2/2026 | 17/6/2026 | The Whatsiplus Scheduled Notification for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing nonce validation on the 'wsnfw_save_users_settings' AJAX action. This makes it possible for unauthenticated attackers to modify… | |
| Aplazada | Media (5.3) | 0.37% | — | Razorpay FOR WoocommerceAI | 19/2/2026 | 17/6/2026 | The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the getCouponList() function in all versions up to, and including, 4.7.8. This is due to the checkAuthCredentials() permission callback always returning true, providing no actual… | |
| Aplazada | Media (6.4) | 0.28% | — | Printful Integration FOR WoocommerceAI | 19/2/2026 | 17/6/2026 | The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.11 via the advanced size chart REST API endpoint. This is due to insufficient validation of user-supplied URLs before passing them to the download_url() function. This… | |
| Aplazada | Alta (7.2) | 0.63% | — | Wpdesk Product Addons FOR WoocommerceAI | 18/2/2026 | 17/6/2026 | The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 3.1.0. This is due to insufficient input validation of the 'operator' field in conditional logic rules within the evalConditions() function, which passes… | |
| Aplazada | Alta (7.2) | 0.51% | — | Villatheme Cart ALL IN ONE FOR WoocommerceAI | 18/2/2026 | 17/6/2026 | The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.1.21. This is due to insufficient input validation on the 'Assign page' field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.24% | — | Order Splitter FOR WoocommerceAI | 18/2/2026 | 17/6/2026 | The Order Splitter for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wos_troubleshooting' AJAX endpoint in all versions up to, and including, 5.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Alta (7.7) | 0.53% | — | Zarinpal Gateway FOR WoocommerceAI | 17/2/2026 | 17/6/2026 | The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and including 5.0.16. This is due to the payment callback handler 'Return_from_ZarinPal_Gateway' failing to validate that the authority token provided in the callback URL… | |
| Aplazada | Alta (7.5) | 0.81% | — | Flexi Product Slider AND Grid FOR WoocommerceAI | 14/2/2026 | 17/6/2026 | The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.5 via the `flexipsg_carousel` shortcode. This is due to the `theme` parameter being directly concatenated into a file path without proper sanitization or validation,… | |
| Aplazada | Alta (7.5) | 0.75% | 💥 Exploit | Bluesnap Payment Gateway FOR WoocommerceAI | 14/2/2026 | 17/6/2026 | The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.4.0. This is due to the plugin relying on WooCommerce's `WC_Geolocation::get_ip_address()` function to validate IPN requests, which trusts user-controllable headers like… | |
| Aplazada | Alta (7.2) | 0.27% | — | Cusrev Customer Reviews FOR WoocommerceAI | 12/2/2026 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].href' parameter in all versions up to, and including, 5.97.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers (if 'Enable for Guests'… | |
| Aplazada | Media (6.5) | 0.33% | — | Openpix FOR WoocommerceAI | 11/2/2026 | 17/6/2026 | The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that reset payment gateway configuration options without capability or nonce checks. This permits any authenticated users, such as subscribers to clear API credentials and webhook status, causing… | |
| Aplazada | Media (4.9) | 0.38% | — | Sibs Woocommerce Payment GatewayAI | 4/2/2026 | 17/6/2026 | The SIBS woocommerce payment gateway plugin for WordPress is vulnerable to time-based SQL Injection via the ‘referencedId’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Media (5.3) | 0.23% | — | Wpfactory Advanced Woocommerce Product Sales ReportingAI | 3/2/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Retrieve Embedded Sensitive Data.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <= 4.1.2. | |
| Aplazada | Media (4.4) | 0.28% | — | Order Minimum Maximum Amount Limits FOR WoocommerceAI | 28/1/2026 | 17/6/2026 | The Order Minimum/Maximum Amount Limits for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Shop Manager-level… | |
| Aplazada | Media (5.3) | 0.41% | — | Wizit Gateway FOR WoocommerceAI | 24/1/2026 | 6/8/2026 | The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in all versions up to, and including, 1.3.1. This is due to a lack of authentication and authorization checks in the 'handle_checkout_redirecturl_response' function. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.22% | — | Imaginate-solutions File Uploads Addon FOR WoocommerceAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Imaginate Solutions File Uploads Addon for WooCommerce woo-addon-uploads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects File Uploads Addon for WooCommerce: from n/a through <= 1.7.3. |