Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
3237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 1.6% | 💥 Exploit | Hippoo Mobile APP FOR WoocommerceAI | 11/6/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4. | |
| Aplazada | Media (4.3) | 0.11% | — | Wedevs Woocommerce Conversion TrackingAI | 11/6/2026 | 29/9/2026 | Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forgery. This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.10. | |
| Aplazada | Media (4.6) | 0.14% | — | Yith Woocommerce Product Slider CarouselAI | 11/6/2026 | 29/9/2026 | Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Request Forgery. This issue affects YITH WooCommerce Product Slider Carousel: from n/a through 1.16.0. | |
| Aplazada | Alta (8.1) | 0.88% | — | Recover Exit FOR WoocommerceAI | 9/6/2026 | 23/7/2026 | The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to insufficient validation and sanitization of the user-controlled `tpf` POST parameter before it is used in an `include()` path in the `recover_exit()` function. This… | |
| Aplazada | Crítica (9.8) | 2.9% | 💥 Exploit | Hippoo Mobile APP FOR WoocommerceAI | 5/6/2026 | 17/6/2026 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the same null sentinel for both… | |
| Aplazada | Crítica (10) | 2.0% | 💥 Exploit | Shapedplugin LLC Product Slider PRO FOR WoocommerceAI | 5/6/2026 | 23/7/2026 | Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4. | |
| Aplazada | Media (5.5) | 0.28% | — | Sourcecodester Pizzafy E-commerce SystemAI | 3/6/2026 | 22/7/2026 | A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed… | |
| Aplazada | Alta (7.1) | 0.37% | — | Wpswings Wallet System FOR WoocommerceAI | 2/6/2026 | 22/7/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System for WooCommerce: from n/a through 2.7.5. | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 2/6/2026 | 22/7/2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation of the argument page can lead to file inclusion. The attack may be performed from remote. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 2/6/2026 | 22/7/2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument page results in file inclusion. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Aplazada | Alta (8.6) | 0.38% | — | Eupago Gateway FOR WoocommerceAI | 28/5/2026 | 17/6/2026 | The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request handler, allowing unauthenticated attackers to initiate refunds against any WooCommerce order using the merchant's payment gateway credentials, and for applicable payment methods, to redirect… | |
| Aplazada | Media (4.3) | 0.22% | — | Bizswoop Account Manager FOR WoocommerceAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Account Manager for WooCommerce: from n/a through 2.1.2. | |
| Aplazada | Media (4.7) | 0.28% | — | Facebook FOR WoocommerceAI | 27/5/2026 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. This issue affects Facebook for WooCommerce: from n/a through 3.7.0. | |
| Aplazada | Media (4.3) | 0.29% | — | Webtoffee Product Import Export FOR WoocommerceAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Import Export for WooCommerce: from n/a through 2.5.6. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Pluginus Active Products Tables FOR WoocommerceAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.9. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Pluginus Active Products Tables FOR WoocommerceAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.8. | |
| Aplazada | Alta (7.1) | 0.18% | — | Jthemes Themebox - Digital Products EcommerceAI | 27/5/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Themebox - Digital Products Ecommerce allows Reflected XSS. This issue affects Themebox - Digital Products Ecommerce: from n/a through 1.4.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Aa-team Woocommerce Envato AffiliatesAI | 26/5/2026 | 24/7/2026 | Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Woocommerce Envato Affiliates: from n/a through 1.2.1. | |
| Aplazada | Media (5.3) | 0.19% | — | Magepeople Taxi Booking Manager FOR WoocommerceAI | 26/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.1. | |
| Aplazada | Alta (7.5) | 0.38% | — | Webtoffee Smart Coupons FOR WoocommerceAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0. | |
| Aplazada | Media (6.5) | 0.46% | — | Themehigh Stripe Payment Gateway FOR WoocommerceAI | 25/5/2026 | 24/7/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommerce allows Password Recovery Exploitation. This issue affects Stripe Payment Gateway for WooCommerce: from n/a through 5.0.7. | |
| Aplazada | Media (4.3) | 0.20% | — | Patternsinthecloud Autoship Cloud FOR Woocommerce Subscription ProductsAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0. | |
| Aplazada | Alta (8.2) | 0.46% | — | Woocommerce Paypal PaymentsAI | 23/5/2026 | 23/7/2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an… | |
| Aplazada | Crítica (10) | 0.52% | — | Wpswings Gift Cards FOR Woocommerce PROAI | 20/5/2026 | 23/7/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6. | |
| Aplazada | Alta (7.6) | 0.38% | — | Yithemes Yith Woocommerce Product Add-onsAI | 20/5/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Blind SQL Injection. This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.29.0. |