Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
182 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.35% | — | Paypal ShortcodeAI | 21/3/2026 | 17/6/2026 | The Paypal Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'amount' and 'name' shortcode attributes in all versions up to, and including, 0.3. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. The swer_paypal_shortcode()… | |
| Aplazada | Alta (8.5) | 0.36% | — | Codepeople CP Contact Form With PaypalAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-contact-form-with-paypal allows Blind SQL Injection.This issue affects CP Contact Form with Paypal: from n/a through <= 1.3.61. | |
| Aplazada | Media (5.3) | 0.29% | — | Noor Alam Checkout-for-paypalAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Noor Alam Checkout for PayPal checkout-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout for PayPal: from n/a through <= 1.0.46. | |
| Aplazada | Media (5.3) | 0.36% | — | Paypalcheckout Payment Button FOR PaypalAI | 17/1/2026 | 17/6/2026 | The Payment Button for PayPal plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 1.2.3.41. This is due to the plugin exposing a public AJAX endpoint (`wppaypalcheckout_ajax_process_order`) that processes checkout results without any authentication or server-side… | |
| Aplazada | Media (4.7) | 0.49% | 💥 Exploit | Scott Paterson Accept Donations With Paypal AND StripeAI | 24/12/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Phishing.This issue affects Accept Donations with PayPal & Stripe: from n/a through <= 1.5.2. | |
| Aplazada | Media (6.4) | 0.22% | — | Paypal Payment ShortcodeAI | 12/12/2025 | 17/6/2026 | The Paypal Payment Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttom_image' parameter of the [paypal-shortcode] shortcode in all versions up to, and including, 1.01 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.25% | — | Easy Payment WOO Paypal GatewayAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Easy Payment Payment Gateway for PayPal on WooCommerce woo-paypal-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway for PayPal on WooCommerce: from n/a through <= 9.0.53. | |
| Aplazada | Alta (7.5) | 0.32% | — | SKT PaypalAI | 27/11/2025 | 17/6/2026 | The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 1.4. This is due to the plugin only enforcing client side controls instead of server-side controls when processing payments. This makes it possible for unauthenticated attackers to make confirmed… | |
| Aplazada | Alta (7.5) | 0.36% | — | CP Contact Form With PaypalAI | 22/11/2025 | 17/6/2026 | The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.56. This is due to the plugin exposing an unauthenticated IPN-like endpoint (via the 'cp_contactformpp_ipncheck' query parameter) that processes payment confirmations without any… | |
| Aplazada | Media (5.3) | 0.17% | — | Subscriptions Memberships FOR PaypalAI | 22/11/2025 | 17/6/2026 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying the authenticity of an IPN request. This makes it possible for unauthenticated attackers to create fake payment entries… | |
| Aplazada | Media (5.3) | 0.22% | — | Scott Paterson Subscriptions AND Memberships FOR PaypalAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscriptions & Memberships for PayPal: from n/a through <= 1.1.7. | |
| Aplazada | Media (6.4) | 0.18% | — | Paypal Donation ShortcodeAI | 11/11/2025 | 17/6/2026 | The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in all versions up to, and including, 0.1. This is due to the plugin not properly sanitizing user input and output of the 'title' and 'text' parameters. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.15% | — | Paypal FormsAI | 3/10/2025 | 30/9/2026 | The PayPal Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing nonce validation on the form creation and management functions. This makes it possible for unauthenticated attackers to create new PayPal forms and modify PayPal payment… | |
| Aplazada | Media (4.3) | 0.13% | — | Fullworksplugins Quick Paypal PaymentsAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in fullworks Quick Paypal Payments quick-paypal-payments allows Cross Site Request Forgery.This issue affects Quick Paypal Payments: from n/a through <= 5.7.46. | |
| Aplazada | Media (5.9) | 0.18% | — | Wp-ecommerce Recurring Paypal DonationsAI | 22/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce Recurring PayPal Donations recurring-donation allows Stored XSS.This issue affects Recurring PayPal Donations: from n/a through <= 1.8. | |
| Aplazada | Media (6.1) | 0.15% | — | Avishi WP Paypal Payment ButtonAI | 19/7/2025 | 17/6/2026 | The Avishi WP PayPal Payment Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing or incorrect nonce validation on the 'avishi-wp-paypal-payment-button/index.php' page. This makes it possible for unauthenticated attackers to update… | |
| Aplazada | Media (4.3) | 0.16% | — | Yithemes Yith Paypal Express Checkout FOR WoocommerceAI | 17/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH PayPal Express Checkout for WooCommerce allows Cross Site Request Forgery. This issue affects YITH PayPal Express Checkout for WooCommerce: from n/a through 1.49.0. | |
| Aplazada | Media (6.5) | 0.20% | — | Charly Leetham Enhanced Paypal ShortcodesAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CharlyLeetham Enhanced Paypal Shortcodes enhanced-paypal-shortcodes allows Stored XSS.This issue affects Enhanced Paypal Shortcodes: from n/a through <= 0.5a. | |
| Modificada | Media (4.8) | 0.28% | — | Wpplugin Easy Paypal & Stripe BUY NOW Button | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Easy PayPal Buy Now Button wp-ecommerce-paypal allows Stored XSS.This issue affects Easy PayPal Buy Now Button: from n/a through <= 2.0. | |
| Aplazada | Media (4.3) | 0.17% | — | Wpplugin Easy Paypal EventsAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal Events easy-paypal-events-tickets allows Cross Site Request Forgery.This issue affects Easy PayPal Events: from n/a through <= 1.2.2. | |
| Aplazada | Media (5.9) | 0.27% | — | Scott Paterson Contact Form 7 Paypal Stripe ADD ONAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on contact-form-7-paypal-add-on allows Stored XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through <= 2.3.4. | |
| Modificada | Media (6.1) | 0.15% | — | Wpplugin Accept Donations With Paypal | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Stored XSS.This issue affects Accept Donations with PayPal & Stripe: from n/a through <= 1.4.5. | |
| Analizada | Media (5.4) | 0.28% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 1/5/2025 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' shortcode in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.3) | 0.36% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 1/5/2025 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 via the 'process_payment_data' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the quantity of a… | |
| Analizada | Media (6.5) | 0.41% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 1/5/2025 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 due to lack of randomization of a user controlled key. This makes it possible for unauthenticated attackers to access customer shopping carts and edit product links, add… |