Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

1856 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.13%—Yith Woocommerce TAB ManagerAI30/9/202630/9/2026
Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.
AplazadaAlta (7.6)0.28%—Quanticedgesolutions Category Discount WoocommerceAI30/9/202630/9/2026
Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.
AplazadaAlta (7.5)0.32%—Cusrev Customer Reviews FOR WoocommerceAI30/9/202630/9/2026
Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
AplazadaAlta (7.1)0.18%—Trusted Shops Easy Integration FOR WoocommerceAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.
AplazadaAlta (7.1)0.18%—Yithemes Yith Woocommerce Ajax SearchAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.
AplazadaAlta (7.2)0.40%—Kadencewp Kadence Woocommerce Email DesignerAI30/9/202630/9/2026
Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.
AplazadaAlta (7.2)0.37%—Wpfactory Cost OF Goods FOR WoocommerceAI30/9/202630/9/2026
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
AplazadaAlta (7.2)0.37%—Minimum AND Maximum Quantity FOR WoocommerceAI30/9/202630/9/2026
Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.
AplazadaAlta (7.2)0.37%—Music Player FOR WoocommerceAI30/9/202630/9/2026
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
AplazadaMedia (5.4)0.17%—Blacklist Manager FOR WoocommerceAI28/9/202628/9/2026
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
AplazadaMedia (5.3)0.24%—Mailchimp FOR WoocommerceAI27/9/202628/9/2026
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the…
AplazadaCrítica (9.8)0.41%💥 PoCAfrfq Request A Quote FOR WoocommerceAI26/9/202628/9/2026
The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied…
AplazadaCrítica (9.1)0.39%💥 PoCCusrev Customer Reviews FOR WoocommerceAI25/9/202625/9/2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete…
AplazadaMedia (6.5)0.17%—Custom Thank YOU Page FOR WoocommerceAI24/9/202624/9/2026
The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to export or reset(delete) the…
AplazadaMedia (6.5)0.28%—Yith Woocommerce Request A QuoteAI23/9/202623/9/2026
Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n/a before 4.46.1.
AplazadaMedia (5.3)0.11%—Paymob FOR WoocommerceAI23/9/202623/9/2026
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce orders as paid without any payment.
AplazadaMedia (4.3)0.15%—Wpswings Points AND Rewards FOR WoocommerceAI23/9/202623/9/2026
The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim handler, allowing authenticated users, Subscriber and above, to credit their own account with an arbitrary and unlimited amount of loyalty points and, where a…
AplazadaMedia (5.3)0.21%—Product Badge Label Countdown Timer FOR WoocommerceAI23/9/202623/9/2026
The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products.
AplazadaMedia (4.7)0.17%—Paymob FOR WoocommerceAI23/9/202623/9/2026
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX actions that manage its payment-gateway configuration, allowing users with contributor-level access to delete, wipe, or modify that configuration, including the stored payment credentials.
AplazadaMedia (5.3)0.20%—Paymob FOR WoocommerceAI23/9/202623/9/2026
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers to write a card-token record to any user's account and to enumerate registered accounts.
AplazadaMedia (5.3)0.18%—Social Commerce FOR WoocommerceAI23/9/202623/9/2026
The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for WooCommerce WordPress plugin through 2.5.4 configuration and product synchronisation state.
AplazadaMedia (6.5)0.20%—Payment Plugins FOR Paypal WoocommerceAI23/9/202623/9/2026
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, allowing unauthenticated attackers to have another buyer's approved but uncaptured…
AplazadaAlta (7.3)0.40%—Magepeople Taxi Booking Manager FOR WoocommerceAI22/9/202622/9/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8.
AplazadaMedia (5.3)0.16%—Angelleye Payment Gateway FOR Paypal ON WoocommerceAI21/9/202622/9/2026
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own…
AplazadaMedia (4.3)0.35%—Partial Shipment FOR WoocommerceAI19/9/202621/9/2026
The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX actions. This is due to the AJAX handlers in woocommerce-partial-shipment.php (registered at lines…
Orbitaley — Vulnerabilidades