Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

105 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.82%—Wpclever WPC Product Carousel SliderAI12/12/202417/6/2026
The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.10 via the 'theme' attribute of the `wcpcsu` shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AplazadaMedia (6.1)0.21%—Wpclever WPC Order NotesAI11/12/202417/6/2026
The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the ajax_update_order_note() function. This makes it possible for unauthenticated attackers to inject malicious web…
ModificadaMedia (5.4)0.24%—Cleversoft Clever Addons FOR Elementor10/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zootemplate Clever Addons for Elementor cafe-lite allows Stored XSS.This issue affects Clever Addons for Elementor: from n/a through <= 2.2.1.
AnalizadaAlta (8.8)0.38%—Wpclever WPC Frequently Bought Together FOR Woocommerce1/11/202417/6/2026
Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Frequently Bought Together for WooCommerce: from n/a through 7.1.9.
AplazadaMedia (4.3)0.36%—Wpclever WPC Smart MessagesAI29/10/202417/6/2026
The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to unauthorized Smar Message activation/deactivation due to a missing capability check on the ajax_enable function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaAlta (8.8)0.75%—Wpclever WPC Smart MessagesAI29/10/202417/6/2026
The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.1 via the get_condition_value function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the…
ModificadaAlta (8.8)0.50%—Wpclever WPC Shop AS A Customer FOR Woocommerce28/10/202417/6/2026
Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through <= 1.2.6.
AplazadaMedia (4.3)0.43%—Clever AddonsAI26/10/202417/6/2026
The Clever Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.1 via the getTemplateContent function in src/widgets/class-clever-widget-base.php. This makes it possible for authenticated attackers, with Contributor-level access and above,…
AnalizadaMedia (4.8)0.26%—Cleversoft Clever Addons FOR Elementor18/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CleverSoft Clever Addons for Elementor allows Stored XSS.This issue affects Clever Addons for Elementor: from n/a through 2.2.0.
ModificadaAlta (8.8)0.32%—Wpclever WPC Badge Management FOR Woocommerce9/6/202417/6/2026
Missing Authorization vulnerability in WPClever WPC Badge Management for WooCommerce.This issue affects WPC Badge Management for WooCommerce: from n/a through 2.4.0.
ModificadaMedia (5.4)0.26%—Nayrathemes Clever FOX7/6/202417/6/2026
The Clever Fox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's info box block in all versions up to, and including, 25.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level…
ModificadaMedia (5.4)0.39%—Nayrathemes Clever FOX7/6/202417/6/2026
The Clever Fox – One Click Website Importer by Nayra Themes plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clever-fox-activate-theme' function in all versions up to, and including, 25.2.0. This makes it possible for authenticated attackers, with…
ModificadaMedia (5.4)0.33%—Cleversoft Clever Addons FOR Elementor6/6/202417/6/2026
The Clever Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CAFE Icon, CAFE Team Member, and CAFE Slider widgets in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.4)0.34%—Wpclever WPC Composite ProductsAI27/4/202417/6/2026
The WPC Composite Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wooco_components[0][name]' parameter in all versions up to, and including, 7.2.7 due to insufficient input sanitization and output escaping and missing authorization on the ajax_save_components…
AplazadaMedia (4.3)0.37%—Wpclever WPC Frequently Bought TogetherAI22/4/202417/6/2026
Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce.This issue affects WPC Frequently Bought Together for WooCommerce: from n/a through 7.0.3.
AplazadaMedia (4.3)0.34%—Wpclever WPC Grouped Product FOR WoocommerceAI17/4/202417/6/2026
Missing Authorization vulnerability in WPClever WPC Grouped Product for WooCommerce.This issue affects WPC Grouped Product for WooCommerce: from n/a through 4.4.2.
ModificadaAlta (8.8)0.24%—Cleverplugins SEO Booster15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in cleverplugins.Com SEO Booster.This issue affects SEO Booster: from n/a through 3.8.9.
ModificadaMedia (4.4)0.33%—Wpclever WPC Smart Quick View FOR Woocommerce13/4/202417/6/2026
The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…
ModificadaAlta (8.8)0.23%—Wpclever WPC Product Bundles FOR Woocommerce5/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Product Bundles for WooCommerce.This issue affects WPC Product Bundles for WooCommerce: from n/a through 7.3.1.
ModificadaCrítica (9.8)0.51%—Cleverplugins Delete Duplicate Posts19/12/202317/6/2026
Missing Authorization vulnerability in Clever plugins Delete Duplicate Posts allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Delete Duplicate Posts: from n/a through 4.8.9.
ModificadaMedia (6.1)0.24%—Cyberws Cleverwise Daily Quotes13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Jeremy O'Connell Cleverwise Daily Quotes allows Stored XSS.This issue affects Cleverwise Daily Quotes: from n/a through 3.2.
ModificadaAlta (8.8)0.31%—Wpclever WPC Smart Wishlist FOR Woocommerce9/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions.
ModificadaMedia (6.1)0.85%—Clevertap15/7/202317/6/2026
CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker. This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them.
ModificadaCrítica (9.8)1.1%—Clever Underscore.deep28/6/202217/6/2026
Underscore.deep is a collection of Underscore mixins that operate on nested objects. Versions of `underscore.deep` prior to version 0.5.3 are vulnerable to a prototype pollution vulnerability. An attacker can craft a malicious payload and pass it to `deepFromFlat`, which would pollute any future Objects created. Any…
ModificadaCrítica (9.8)1.0%—Biscuitsec Biscuit-authBiscuitsec Biscuit-goBiscuitsec Biscuit-haskellClever-cloud Biscuit-java13/6/202217/6/2026
Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algorithm that allows malicious actors to forge valid Γ-signatures. Such an attack would allow an attacker to create a token with any access level. The version 2 of the…
Orbitaley — Vulnerabilidades