Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

3237 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.35%—Subscriptions FOR WoocommerceAI26/6/202629/6/2026
Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.
AplazadaAlta (7.5)0.42%—Wpfactory Print Invoice AND Delivery Notes FOR WoocommerceAI26/6/202626/6/2026
Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.
AplazadaMedia (6.5)0.33%—Woocart Payment Gateway Based Fees AND Discounts FOR WoocommerceAI26/6/202629/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.
AplazadaAlta (7.1)0.25%—Cusrev Customer Reviews FOR WoocommerceAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.
AplazadaAlta (7.5)0.43%—Corvuspay Woocommerce Payment GatewayAI26/6/202626/6/2026
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
AplazadaCrítica (9.9)0.48%—Booster FOR WoocommerceAI26/6/202626/6/2026
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
AplazadaAlta (7.5)0.35%—Paymob FOR WoocommerceAI26/6/202626/6/2026
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
AplazadaMedia (6.5)0.33%—Themeisle Ppom FOR WoocommerceAI25/6/202625/6/2026
Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18.
AplazadaAlta (7.1)0.25%—Algolplus Advanced Order Export FOR WoocommerceAI25/6/202625/6/2026
Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.
AplazadaMedia (6.5)0.33%—Wpexperts License Manager FOR WoocommerceAI25/6/202629/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
AplazadaCrítica (9.3)0.40%—Premmerce Wishlist FOR WoocommerceAI25/6/202625/6/2026
Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.
AplazadaAlta (8.3)0.32%—Saad Iqbal Apiexperts Square FOR WoocommerceAI25/6/202625/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.
AplazadaMedia (6.4)0.33%—Avalon23 Products Filter FOR WoocommerceAI24/6/202625/6/2026
The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and including, 1.1.6. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes (notably 'title' and…
AplazadaAlta (7.5)0.43%—Shapedsmart Smart Post Show PROAIReal Testimonials PROAIProduct Slider FOR Woocommerce PROAI24/6/202625/6/2026
Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for…
AplazadaMedia (6.1)0.25%—Akin Software E-commerceAI23/6/202623/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. E-Commerce allows Reflected XSS. This issue affects e-Commerce: before 1.25.01.06.
AplazadaAlta (7.1)0.25%—Ultimate Woocommerce Auction PROAI22/6/202622/6/2026
The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaMedia (6.1)0.25%—Ultimate-woocommerce-auction-pro Ultimate Woocommerce Auction PROAI22/6/202622/6/2026
The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaCrítica (9.3)1.1%—WoocommerceAI20/6/20266/10/2026
WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious…
AplazadaMedia (4.9)0.59%—Woosa Marktplaats FOR WoocommerceAI19/6/202623/6/2026
The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in versions up to and including 2.0.4. This is due to insufficient path sanitization in the render_logs_ui() function, which accepts a base64-encoded file name from the 'log_file' GET parameter and…
AplazadaMedia (6.1)0.21%—Sysbasics Customize MY Account FOR WoocommerceAI18/6/202618/6/2026
The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 4.3.6 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaMedia (6.4)0.19%—Sysbasics Customize MY Account FOR WoocommerceAI18/6/202618/6/2026
The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode in versions up to, and including, 4.3.6. This is due to insufficient input sanitization and output escaping on user supplied attributes (min_height, min_width,…
AplazadaMedia (4.9)0.47%—Algolplus Advanced Order Export FOR WoocommerceAI18/6/202618/6/2026
The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_direction' parameter in all versions up to, and including, 4.0.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaMedia (6.9)0.28%—SimplcommerceAI17/6/202618/6/2026
Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an administrator via a crafted form submitted to `/api/news-items`, due to missing anti-CSRF protection.
AplazadaCrítica (9.3)0.40%—Cargo RD Cargo Shipping Location FOR WoocommerceAI17/6/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.
AplazadaCrítica (9.8)0.48%💥 PoCRegistration Form FOR WoocommerceAI17/6/202617/6/2026
Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.