Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.26% | — | Coderpress Commerce Coinbase FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in CoderPress Commerce Coinbase For WooCommerce commerce-coinbase-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Commerce Coinbase For WooCommerce: from n/a through <= 1.6.6. | |
| Aplazada | Media (6.8) | 0.35% | — | Add-ons.org Products-file-upload-for-woocommerceAI | 25/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Product File Upload for WooCommerce products-file-upload-for-woocommerce allows Path Traversal.This issue affects Product File Upload for WooCommerce: from n/a through <= 2.2.4. | |
| Aplazada | Alta (7.5) | 0.33% | — | Tychesoftwares Woocommerce Delivery NotesAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.9.0. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Wpfactory Advanced Woocommerce Product Sales ReportingAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Blind SQL Injection.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <=… | |
| Aplazada | Alta (7.5) | 0.46% | — | Wpswings Subscriptions FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce allows Input Data Manipulation.This issue affects Subscriptions for WooCommerce: from n/a through <= 1.8.10. | |
| Aplazada | Alta (7.5) | 0.37% | — | Wpfactory Helpdesk Support Ticket System FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.2. | |
| Aplazada | Media (6.5) | 0.30% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.0. | |
| Aplazada | Alta (7.2) | 0.50% | — | Webtoffee Product Feed FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Object Injection.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.3. | |
| Aplazada | Media (6.5) | 0.48% | — | WBW Product Filter FOR WoocommerceAI | 24/3/2026 | 17/6/2026 | The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check in all versions up to, and including, 3.1.2. This is due to the plugin's MVC framework dynamically registering unauthenticated AJAX handlers via `wp_ajax_nopriv_` hooks without… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester E-commerce SiteAI | 24/3/2026 | 17/6/2026 | A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /products.php. The manipulation of the argument Search results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Aplazada | Crítica (9.8) | 0.99% | 💥 PoC | Woocommerce Custom Product Addons PROAI | 24/3/2026 | 17/6/2026 | The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_custom_formula() function within includes/process/price.php. This is due to insufficient sanitization and validation of… | |
| Aplazada | Alta (7.5) | 0.43% | — | Multidots Fraud Prevention FOR WoocommerceAI | 19/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fraud Prevention For Woocommerce: from n/a through <= 2.3.3. | |
| Aplazada | Crítica (9.8) | 1.8% | 💥 Exploit | Rymera WEB CO PTY LTD Woocommerce Wholesale Lead CaptureAI | 19/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1. | |
| Aplazada | Crítica (9) | 1.6% | 💥 PoC | Rymera WEB CO PTY LTD Woocommerce Wholesale Lead CaptureAI | 19/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1. | |
| Aplazada | Media (5.3) | 0.31% | — | Wpswings Subscriptions FOR WoocommerceAI | 18/3/2026 | 17/6/2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wps_sfw_admin_cancel_susbcription()` function in all versions up to, and including, 1.9.2. This is due to the function being hooked to the `init` action without any… | |
| Aplazada | Media (5.3) | 0.38% | — | Booster FOR WoocommerceAI | 17/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booster for WooCommerce: from n/a through < 7.11.3. | |
| Aplazada | Crítica (9.8) | 30% | 💥 Exploit | PIX FOR WoocommerceAI | 13/3/2026 | 17/6/2026 | The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to upload… | |
| Aplazada | Media (5.3) | 0.29% | — | Wombat Advanced Product Fields FOR WoocommerceAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Wombat Plugins Advanced Product Fields (Product Addons) for WooCommerce advanced-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Product Fields (Product Addons) for WooCommerce: from n/a through <=… | |
| Aplazada | Media (6.5) | 0.22% | — | Pluginus Active Products Tables FOR WoocommerceAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows DOM-Based XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.7. | |
| Aplazada | Media (5.4) | 0.22% | — | Giftup Gift UP Gift Cards FOR Wordpress AND WoocommerceAI | 13/3/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Gift Up! Gift Up Gift Cards for WordPress and WooCommerce gift-up allows Server Side Request Forgery.This issue affects Gift Up Gift Cards for WordPress and WooCommerce: from n/a through <= 3.1.7. | |
| Aplazada | Media (5.3) | 0.26% | — | Woobewoo WBW Currency Switcher FOR WoocommerceAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WBW Plugins WBW Currency Switcher for WooCommerce woo-currency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WBW Currency Switcher for WooCommerce: from n/a through <= 2.2.5. | |
| Aplazada | Media (6.5) | 0.28% | — | Subrata MAL Terawallet - FOR WoocommerceAI | 13/3/2026 | 17/6/2026 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Subrata Mal TeraWallet – For WooCommerce woo-wallet allows Leveraging Race Conditions.This issue affects TeraWallet – For WooCommerce: from n/a through <= 1.5.15. | |
| Aplazada | Media (4.3) | 0.27% | — | Josh Kohlbach Advanced Coupons FOR Woocommerce CouponsAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for-woocommerce-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Coupons for WooCommerce Coupons: from n/a through <= 4.7.1. | |
| Analizada | Media (6.3) | 0.32% | — | Craftcms Craft Commerce | 11/3/2026 | 17/6/2026 | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (IDOR) vulnerability exists in Craft Commerce’s cart functionality that allows users to hijack any shopping cart by knowing or guessing its 32-character number. The CartController accepts a… | |
| Aplazada | Crítica (9.8) | 0.80% | 💥 PoC | Datalogics Ecommerce DeliveryAI | 11/3/2026 | 17/6/2026 | The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perform arbitrary WordPress… |