Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.57% | — | Cusrev Customer Reviews FOR WoocommerceAI | 10/4/2026 | 17/6/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.103.0. This is due to the `create_review_permissions_check()` function comparing the user-supplied `key` parameter against the order's `ivole_secret_key` meta value using strict… | |
| Aplazada | Alta (7.5) | 1.7% | 💥 Exploit | Wcapf Woocommerce Ajax Product FilterAI | 8/4/2026 | 24/7/2026 | WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in all versions up to, and including, 4.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.38% | — | Eshipper CommerceAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in eshipper eShipper Commerce eshipper-commerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eShipper Commerce: from n/a through <= 2.16.12. | |
| Aplazada | Media (5.3) | 0.31% | — | G5theme Book Previewer FOR WoocommerceAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in g5theme Book Previewer for Woocommerce book-previewer-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Book Previewer for Woocommerce: from n/a through <= 1.0.6. | |
| Aplazada | Media (5.3) | 0.26% | — | Prowcplugins Product Price BY Formula FOR WoocommerceAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in ProWCPlugins Product Price by Formula for WooCommerce product-price-by-formula-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Price by Formula for WooCommerce: from n/a through <= 2.5.6. | |
| Aplazada | Media (5.3) | 0.29% | — | Razorpay FOR WoocommerceAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Razorpay Razorpay for WooCommerce woo-razorpay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay for WooCommerce: from n/a through <= 4.8.2. | |
| Aplazada | Media (5.4) | 0.22% | — | Globalpayments Global Payments WoocommerceAI | 8/4/2026 | 24/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in Global Payments GlobalPayments WooCommerce global-payments-woocommerce allows Server Side Request Forgery.This issue affects GlobalPayments WooCommerce: from n/a through <= 1.18.0. | |
| Aplazada | Media (5.3) | 0.29% | — | Paymentplugins Payment Plugins FOR Paypal WoocommerceAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Payment Plugins Payment Plugins for PayPal WooCommerce pymntpl-paypal-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Plugins for PayPal WooCommerce: from n/a through <= 2.0.13. | |
| Aplazada | Media (5.3) | 0.33% | — | Doofinder FOR WoocommerceAI | 8/4/2026 | 24/7/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Doofinder Doofinder for WooCommerce doofinder-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Doofinder for WooCommerce: from n/a through <= 2.10.13. | |
| Aplazada | Media (6.5) | 0.22% | — | Josh Kohlbach Advanced Coupons FOR WoocommerceAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for-woocommerce-free allows DOM-Based XSS.This issue affects Advanced Coupons for WooCommerce Coupons: from n/a through <= 4.7.1.1. | |
| Aplazada | Media (5.3) | 0.31% | — | Realmag777 FOX Woocommerce Currency SwitcherAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FOX: from n/a through <= 1.4.5. | |
| Aplazada | Alta (7.6) | 0.38% | — | Realmag777 FOX Woocommerce Currency SwitcherAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Blind SQL Injection.This issue affects FOX: from n/a through <= 1.4.5. | |
| Aplazada | Alta (7.6) | 0.38% | — | Yaycommerce YaymailAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayMail yaymail allows Blind SQL Injection.This issue affects YayMail: from n/a through <= 4.3.3. | |
| Aplazada | Crítica (9.1) | 0.24% | — | Order Notification FOR WoocommerceAI | 1/4/2026 | 7/10/2026 | The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers. | |
| Aplazada | Media (6.5) | 0.27% | — | Woocommerce WoopaymentsAI | 31/3/2026 | 17/6/2026 | The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_upe_appearance_ajax' function in all versions up to, and including, 10.5.1. This makes it possible for unauthenticated attackers to update plugin… | |
| Aplazada | Baja (2) | 2.1% | — | Code-projects Chamber OF Commerce Membership Management SystemAI | 29/3/2026 | 17/6/2026 | A vulnerability was identified in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the function fwrite of the file admin/pageMail.php. The manipulation of the argument mailSubject/mailMessage leads to command injection. The attack may be initiated remotely. The exploit is publicly… | |
| Aplazada | Alta (7.1) | 0.25% | — | Villatheme Abandoned Cart Recovery FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Stored XSS.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.10. | |
| Aplazada | Alta (8.6) | 0.53% | — | Vanquish Woocommerce-support-ticket-systemAI | 25/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerce-support-ticket-system allows Path Traversal.This issue affects WooCommerce Support Ticket System: from n/a through < 18.5. | |
| Aplazada | Alta (7.7) | 0.39% | — | Webtoffee Comments Import AND Export WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comments Import & Export: from n/a through <= 2.4.9. | |
| Aplazada | Alta (8.2) | 0.38% | — | Devteam Products-rearrange-woocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Rearrange for WooCommerce: from n/a through <= 1.2.2. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Devteam Product Rearrange FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Blind SQL Injection.This issue affects Product Rearrange for WooCommerce: from n/a through <= 1.2.2. | |
| Aplazada | Alta (8.8) | 0.52% | — | Sbthemes Woocommerce Infinite ScrollAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in sbthemes WooCommerce Infinite Scroll sb-woocommerce-infinite-scroll allows Object Injection.This issue affects WooCommerce Infinite Scroll: from n/a through <= 1.6.2. | |
| Aplazada | Media (6.5) | 0.33% | — | Viabill WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in ViaBill for WooCommerce ViaBill – WooCommerce viabill-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ViaBill – WooCommerce: from n/a through <= 1.1.53. | |
| Aplazada | Media (6.5) | 0.34% | — | Pickplugins Product Slider FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Slider for WooCommerce: from n/a through <= 1.13.61. | |
| Aplazada | Alta (7.5) | 0.43% | — | Snowray Software File Uploader FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader for WooCommerce: from n/a through <= 1.0.4. |