Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1856 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.30% | — | Brevo FOR WoocommerceAI | 8/1/2026 | 17/6/2026 | The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_id’ parameter in all versions up to, and including, 4.0.49 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (8.5) | 0.36% | — | Vanquish Woocommerce Orders AND Customers ExporterAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vanquish WooCommerce Orders & Customers Exporter woocommerce-orders-ei allows SQL Injection.This issue affects WooCommerce Orders & Customers Exporter: from n/a through <= 5.4. | |
| Aplazada | Alta (8.2) | 0.34% | — | Ipaymu Payment Gateway FOR WoocommerceAI | 7/1/2026 | 17/6/2026 | The iPaymu Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 2.0.2 via the 'check_ipaymu_response' function. This is due to the plugin not validating webhook request authenticity through signature verification or origin checks. This makes… | |
| Aplazada | Media (6.4) | 0.26% | — | QR Code FOR Woocommerce Order Emails PDF Invoices Packing SlipsAI | 7/1/2026 | 17/6/2026 | The QR Code for WooCommerce order emails, PDF invoices, packing slips plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 1.9.42 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Aplazada | Media (5.3) | 0.40% | — | Papaki Piraeus Bank Woocommerce Payment GatewayAI | 7/1/2026 | 17/6/2026 | The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modification in all versions up to, and including, 3.1.4. This is due to missing authorization checks on the payment callback endpoint handler when processing the 'fail' callback from the payment gateway. This… | |
| Aplazada | Media (4.4) | 0.33% | — | Email Customizer FOR WoocommerceAI | 7/1/2026 | 17/6/2026 | The Email Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email template content in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access,… | |
| Aplazada | Media (6.1) | 0.31% | — | Premmerce Woocommerce Customers ManagerAI | 7/1/2026 | 17/6/2026 | The Premmerce WooCommerce Customers Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'money_spent_from', 'money_spent_to', 'registered_from', and 'registered_to' parameters in all versions up to, and including, 1.1.14 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Media (6.4) | 0.27% | — | Cusrev Customer Reviews FOR WoocommerceAI | 7/1/2026 | 7/10/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayName' parameter in all versions up to, and including, 5.93.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with customer-level access… | |
| Aplazada | Alta (7.1) | 0.18% | — | Aa-team Woocommerce Sales Funnel BuilderAIAa-team Amazon Affiliates Addon FOR Wpbakery Page BuilderAI | 6/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerce Sales Funnel Builder, AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows Reflected XSS.This issue affects Woocommerce Sales Funnel Builder: from n/a through… | |
| Aplazada | Media (6.5) | 0.16% | — | Wpfactory Wishlist FOR WoocommerceAI | 6/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Stored XSS.This issue affects Wishlist for WooCommerce: from n/a through <= 3.3.0. | |
| Aplazada | Media (5.3) | 0.28% | — | Ilghera Support System FOR WoocommerceAI | 6/1/2026 | 17/6/2026 | The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'delete_single_ticket_callback' and 'change_ticket_status_callback' functions in all versions up to, and including, 1.2.6. This makes it possible for… | |
| Aplazada | Media (6.3) | 0.20% | — | Wpswings Wallet System FOR WoocommerceAI | 5/1/2026 | 7/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for WooCommerce: from n/a through <= 2.7.3. | |
| Aplazada | Media (4.3) | 0.23% | — | Mykola Lukin Orders Chat FOR WoocommerceAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Mykola Lukin Orders Chat for WooCommerce orders-chat-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Orders Chat for WooCommerce: from n/a through <= 1.2.0. | |
| Aplazada | Media (5.3) | 0.25% | — | Channelize Live Shopping AND Shoppable Videos FOR WoocommerceAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2.0. | |
| Aplazada | Media (5.9) | 0.21% | — | Filipe Seabra Woocommerce ParcelasAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Filipe Seabra WooCommerce Parcelas woocommerce-parcelas allows DOM-Based XSS.This issue affects WooCommerce Parcelas: from n/a through <= 1.3.5. | |
| Aplazada | Media (6.5) | 0.16% | — | Wpfactory Maximum Products PER User FOR WoocommerceAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Maximum Products per User for WooCommerce maximum-products-per-user-for-woocommerce allows Stored XSS.This issue affects Maximum Products per User for WooCommerce: from n/a through <= 4.4.3. | |
| Aplazada | Media (6.5) | 0.19% | — | Pagebuilderaddons WEB AND Woocommerce Addons FOR Wpbakery BuilderAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Genetech Products Web and WooCommerce Addons for WPBakery Builder vc-addons-by-bit14 allows DOM-Based XSS.This issue affects Web and WooCommerce Addons for WPBakery Builder: from n/a through <= 1.5. | |
| Aplazada | Alta (7.2) | 0.64% | — | Lucky Wheel FOR WoocommerceAI | 30/12/2025 | 7/10/2026 | The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.1.13. This is due to the plugin using eval() to execute user-supplied input from the 'Conditional Tags' setting without proper validation or sanitization. This makes it… | |
| Aplazada | Media (5.3) | 0.22% | — | Wpdesk Shopmagic FOR WoocommerceAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in wpdesk ShopMagic shopmagic-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShopMagic: from n/a through <= 4.7.2. | |
| Aplazada | Media (5.3) | 0.21% | — | Tychesoftwares Product Delivery Date FOR Woocommerce LiteAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in tychesoftwares Product Delivery Date for WooCommerce – Lite product-delivery-date-for-woocommerce-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through <= 3.2.0. | |
| Aplazada | Media (5.3) | 0.27% | — | Xforwoocommerce Product Loops FOR WoocommerceAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in XforWooCommerce Product Loops for WooCommerce product-loops allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Loops for WooCommerce: from n/a through <= 2.1.2. | |
| Aplazada | Media (5.3) | 0.27% | — | Xforwoocommerce Share Print AND PDF Products FOR WoocommerceAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in XforWooCommerce Share, Print and PDF Products for WooCommerce share-print-pdf-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share, Print and PDF Products for WooCommerce: from n/a through <= 3.1.2. | |
| Aplazada | Media (6.5) | 0.16% | — | Wpfactory Free Shipping BAR Amount Left FOR Free Shipping FOR WoocommerceAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Free Shipping Bar: Amount Left for Free Shipping for WooCommerce amount-left-free-shipping-woocommerce allows Stored XSS.This issue affects Free Shipping Bar: Amount Left for Free Shipping for WooCommerce:… | |
| Aplazada | Alta (8.5) | 0.25% | — | Berocket Brands FOR WoocommerceAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Blind SQL Injection.This issue affects Brands for WooCommerce: from n/a through <= 3.8.6.3. | |
| Aplazada | Alta (7.5) | 0.39% | — | Wpswings Membership FOR WoocommerceAI | 24/12/2025 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Membership For WooCommerce: from n/a through <= 3.0.3. |