Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2671▼ 680 respecto a la semana anterior
Críticas / altas1271▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)230▼ 272 respecto a la semana anterior
1860 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.24% | — | Themewarriors Whatsapp Chat FOR Wordpress AND WoocommerceAI | 22/10/2025 | 8/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeWarriors WhatsApp Chat for WordPress and WooCommerce tw-whatsapp-chat-rotator allows Reflected XSS.This issue affects WhatsApp Chat for WordPress and WooCommerce: from n/a through <= 1.2.1. | |
| Aplazada | Alta (7.1) | 0.24% | — | Aa-team Woocommerce Envato AffiliatesAI | 22/10/2025 | 8/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerce Envato Affiliates wooenvato allows Reflected XSS.This issue affects Woocommerce Envato Affiliates: from n/a through <= 1.2.1. | |
| Aplazada | Media (6.5) | 0.27% | — | Fantasticplugins Sumo Memberships FOR WoocommerceAI | 22/10/2025 | 8/10/2026 | Missing Authorization vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SUMO Memberships for WooCommerce: from n/a through < 7.8.0. | |
| Aplazada | Alta (7.1) | 0.24% | — | Robokassa Payment Gateway FOR WoocommerceAI | 22/10/2025 | 8/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robokassa Robokassa payment gateway for Woocommerce robokassa allows Reflected XSS.This issue affects Robokassa payment gateway for Woocommerce: from n/a through <= 1.8.6. | |
| Aplazada | Alta (7.1) | 0.28% | — | Extendons Woocommerce Registration Fields PluginAI | 22/10/2025 | 8/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields allows Reflected XSS.This issue affects WooCommerce Registration Fields Plugin - Custom Signup Fields: from n/a… | |
| Aplazada | Alta (7.5) | 0.61% | — | Woocommerce Category AND Products Accordion PanelAI | 15/10/2025 | 8/10/2026 | The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0 via the 'categoryaccordionpanel' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute… | |
| Aplazada | Crítica (9.8) | 0.81% | — | Woocommerce Designer PROAI | 11/10/2025 | 17/6/2026 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it… | |
| Aplazada | Crítica (9.8) | 0.47% | 💥 PoC | Appy PIE Connect FOR WoocommerceAI | 3/10/2025 | 30/9/2026 | The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the reset_user_password() REST handler in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to reset the password of arbitrary users,… | |
| Aplazada | Media (6.4) | 0.25% | — | BIG Post Shipping FOR WoocommerceAI | 30/9/2025 | 17/6/2026 | The Big Post Shipping for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wooboigpost_shipping_status' shortcode in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Crítica (10) | 0.39% | — | Harutheme Woocommerce Designer PROAI | 26/9/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro wc-designer-pro allows Upload a Web Shell to a Web Server.This issue affects WooCommerce Designer Pro: from n/a through <= 1.9.24. | |
| Aplazada | Alta (7.1) | 0.12% | — | Ashwani Kumar GST FOR WoocommerceAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ashwani kumar GST for WooCommerce gst-for-woocommerce allows Stored XSS.This issue affects GST for WooCommerce: from n/a through <= 2.0. | |
| Aplazada | Alta (7.1) | 0.12% | — | Yourplugins Conditional Cart Messages FOR WoocommerceAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in yourplugins Conditional Cart Messages for WooCommerce – YourPlugins.com yourplugins-wc-conditional-cart-notices allows Stored XSS.This issue affects Conditional Cart Messages for WooCommerce – YourPlugins.com: from n/a through <= 1.2.10. | |
| Aplazada | Media (4.3) | 0.28% | — | Webmaniabr Nota Fiscal Eletronica WoocommerceAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce nota-fiscal-eletronica-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nota Fiscal Eletrônica WooCommerce: from n/a through <= 3.4.0.9. | |
| Aplazada | Media (5.9) | 0.24% | — | Webmaniabr Nota Fiscal Eletronica WoocommerceAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce nota-fiscal-eletronica-woocommerce allows Stored XSS.This issue affects Nota Fiscal Eletrônica WooCommerce: from n/a through <= 3.4.0.9. | |
| Aplazada | Media (6.5) | 0.20% | — | Nick Verwymeren Quantities AND Units FOR WoocommerceAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Verwymeren Quantities and Units for WooCommerce quantities-and-units-for-woocommerce allows Stored XSS.This issue affects Quantities and Units for WooCommerce: from n/a through <= 1.0.13. | |
| Aplazada | Baja (2.7) | 0.22% | — | Shopengine Elementor Woocommerce Builder AddonAI | 26/9/2025 | 17/6/2026 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 0.37% | — | Multiloca Woocommerce Multi Locations Inventory ManagementAI | 24/9/2025 | 17/6/2026 | The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'wcmlim_settings_ajax_handler' function in all versions up to, and including, 4.2.8. This makes it… | |
| Aplazada | Media (6.5) | 0.21% | — | Wpswings Upsell Order Bump Offer FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Upsell Order Bump Offer for WooCommerce upsell-order-bump-offer-for-woocommerce allows Stored XSS.This issue affects Upsell Order Bump Offer for WooCommerce: from n/a through <= 3.0.7. | |
| Aplazada | Media (4.3) | 0.25% | — | Payrexx Payment Gateway FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in payrexx Payrexx Payment Gateway for WooCommerce woo-payrexx-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payrexx Payment Gateway for WooCommerce: from n/a through <= 3.1.5. | |
| Aplazada | Alta (8.5) | 0.26% | — | Quadlayers Perfect Brands FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce perfect-woocommerce-brands allows SQL Injection.This issue affects Perfect Brands for WooCommerce: from n/a through <= 3.6.2. | |
| Aplazada | Media (5.3) | 0.27% | — | Cecabank WoocommerceAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in cecabank Cecabank WooCommerce Plugin cecabank-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cecabank WooCommerce Plugin: from n/a through <= 0.3.4. | |
| Aplazada | Media (5.3) | 0.29% | — | Risto Niinemets Estonian Shipping Methods FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Risto Niinemets Estonian Shipping Methods for WooCommerce estonian-shipping-methods-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Estonian Shipping Methods for WooCommerce: from n/a through <= 1.7.2. | |
| Aplazada | Media (5.3) | 0.28% | — | Templateinvaders TI Woocommerce WishlistAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.10.0. | |
| Aplazada | Media (6.5) | 0.22% | — | Shapedplugin LLC Quick View FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Quick View for WooCommerce woo-quickview allows Stored XSS.This issue affects Quick View for WooCommerce: from n/a through <= 2.2.16. | |
| Aplazada | Alta (7.1) | 0.15% | — | Wpdesk Flexible PDF Invoices FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible PDF Invoices for WooCommerce & WordPress flexible-invoices allows Cross Site Request Forgery.This issue affects Flexible PDF Invoices for WooCommerce & WordPress: from n/a through <= 6.0.13. |