Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1860 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.24% | — | Funnelkit Funnel Builder FOR Woocommerce CheckoutAI | 19/11/2025 | 17/6/2026 | The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wfop_phone` shortcode in all versions up to, and including, 3.13.1.2. This is due to insufficient input sanitization and output escaping on the user-supplied `default` attribute. This… | |
| Aplazada | Media (5.3) | 0.31% | — | Yithemes Yith Woocommerce WishlistAI | 19/11/2025 | 17/6/2026 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to the plugin not properly verifying that a user is authorized to perform actions on the REST API /wp-json/yith/wishlist/v1/lists endpoint (which uses permission_callback… | |
| Aplazada | Media (5.3) | 0.28% | — | Yithemes Yith Woocommerce WishlistAI | 19/11/2025 | 17/6/2026 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via the REST API endpoint and AJAX handler due to missing validation on user-controlled keys. This makes it possible for unauthenticated attackers to discover any user's… | |
| Aplazada | Media (5.3) | 0.29% | — | Pixel Manager FOR WoocommerceAI | 18/11/2025 | 17/6/2026 | The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.49.2 via the ajax_pmw_get_product_ids() function due to insufficient restrictions on which products can be included. This… | |
| Aplazada | Alta (7.5) | 0.31% | — | Live Sales Notification FOR WoocommerceAI | 18/11/2025 | 17/6/2026 | The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39. This is due to the "getOrders" function lacking proper authorization and capability checks when the plugin is configured to display recent order information. This makes… | |
| Aplazada | Alta (8.8) | 0.33% | — | Category AND Product Woocommerce TabsAI | 18/11/2025 | 17/6/2026 | The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0. This is due to insufficient input validation on the 'template' parameter in the categoryProductTab() function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.20% | — | Webtoffee Order Export AND Order Import FOR WoocommerceAI | 13/11/2025 | 7/10/2026 | Missing Authorization vulnerability in WebToffee Order Export & Order Import for WooCommerce order-import-export-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Export & Order Import for WooCommerce: from n/a through <= 2.6.7. | |
| Modificada | Media (6.5) | 0.16% | — | Booster FOR Woocommerce | 13/11/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Stored XSS.This issue affects Booster for WooCommerce: from n/a through <= 7.3.2. | |
| Modificada | Media (4.3) | 0.19% | — | Booster FOR Woocommerce | 13/11/2025 | 7/10/2026 | Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booster for WooCommerce: from n/a through <= 7.4.0. | |
| Aplazada | Media (4.3) | 0.21% | — | Wpswings Woocommerce Ultimate Points AND RewardsAI | 13/11/2025 | 7/10/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPSwings WooCommerce Ultimate Points And Rewards woocommerce-ultimate-points-and-rewards allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce Ultimate Points And Rewards: from n/a through <= 2.10.2. | |
| Aplazada | Alta (7.5) | 0.44% | — | Paymentplugins Braintree FOR WoocommerceAI | 12/11/2025 | 17/6/2026 | The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wc-braintree/v1/3ds/vaulted_nonce REST API endpoint in all versions up to, and including, 3.2.78. This is due to the endpoint being registered with permission_callback set… | |
| Aplazada | Media (4.3) | 0.19% | — | Wishlist AND Save FOR Later FOR WoocommerceAI | 12/11/2025 | 17/6/2026 | The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.22 via the 'awwlm_remove_added_wishlist_page' AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.28% | — | Make Email Customizer FOR WoocommerceAI | 11/11/2025 | 7/10/2026 | The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, such as a Subscriber, to update arbitrary WordPress options. | |
| Aplazada | Media (6.4) | 0.22% | — | Woocommerce Products BY Custom TAXAI | 11/11/2025 | 17/6/2026 | The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_products_custom_tax' shortcode in all versions up to, and including, 2.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.15% | — | USB QR Code Scanner FOR WoocommerceAI | 11/11/2025 | 7/10/2026 | The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation on the settings page. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request… | |
| Modificada | Alta (7.1) | 0.19% | — | Booster FOR Woocommerce | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Reflected XSS.This issue affects Booster for WooCommerce: from n/a through <= 7.2.5. | |
| Aplazada | Crítica (9.1) | 0.47% | — | Acowebs Dynamic Pricing With Discount Rules FOR WoocommerceAI | 6/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce aco-woo-dynamic-pricing allows Code Injection.This issue affects Dynamic Pricing With Discount Rules for WooCommerce: from n/a through <= 4.5.9. | |
| Aplazada | Media (6.5) | 0.31% | — | BUX WoocommerceAI | 6/11/2025 | 7/10/2026 | Missing Authorization vulnerability in Bux Bux Woocommerce bux-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bux Woocommerce: from n/a through <= 1.2.3. | |
| Aplazada | Crítica (9.8) | 0.44% | — | Holest Engineering Selling Commander FOR WoocommerceAI | 6/11/2025 | 7/10/2026 | Incorrect Privilege Assignment vulnerability in Holest Engineering Selling Commander for WooCommerce selling-commander-connector allows Privilege Escalation.This issue affects Selling Commander for WooCommerce: from n/a through <= 1.2.46. | |
| Aplazada | Crítica (10) | 0.46% | — | Plugify Support Ticket System FOR WoocommerceAI | 6/11/2025 | 7/10/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Plugify Support Ticket System for WooCommerce (Premium) support-ticket-system-for-woocommerce allows Using Malicious Files.This issue affects Support Ticket System for WooCommerce (Premium): from n/a through <= 2.0.7. | |
| Aplazada | Crítica (10) | 0.46% | — | Addify Custom User Registration Fields FOR WoocommerceAI | 6/11/2025 | 7/10/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Addify Custom User Registration Fields for WooCommerce user-registration-plugin-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Custom User Registration Fields for WooCommerce: from n/a through <= 2.1.2. | |
| Aplazada | Alta (7.5) | 0.46% | — | Josh Kohlbach Woocommerce Store ToolkitAI | 6/11/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Josh Kohlbach WooCommerce Store Toolkit woocommerce-store-toolkit allows PHP Local File Inclusion.This issue affects WooCommerce Store Toolkit: from n/a through <= 2.4.3. | |
| Aplazada | Alta (7.5) | 0.46% | — | Premmerce Product Search FOR WoocommerceAI | 6/11/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows PHP Local File Inclusion.This issue affects Premmerce Product Search for WooCommerce: from n/a through <= 2.2.4. | |
| Aplazada | Alta (7.1) | 0.23% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 6/11/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Reflected XSS.This issue affects Booking and Rental Manager: from n/a through <= 2.5.3. | |
| Aplazada | Media (4.3) | 0.20% | — | Sidngr Import Export FOR WoocommerceAI | 4/11/2025 | 17/6/2026 | The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_setting() function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update… |