Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

3236 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.17%—Custom Thank YOU Page FOR WoocommerceAI24/9/202624/9/2026
The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to export or reset(delete) the…
AplazadaMedia (6.5)0.28%—Yith Woocommerce Request A QuoteAI23/9/202623/9/2026
Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n/a before 4.46.1.
AplazadaAlta (7)0.25%—Isotope EcommerceAIContaoAI23/9/202624/9/2026
Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administrator-supplied values directly into SQL statements. Authenticated Contao backend users with Isotope module permissions can exploit conditional and time-based…
AplazadaAlta (8.2)0.38%—Isotope EcommerceAI23/9/202624/9/2026
Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, allowing unauthenticated attackers to guess identifiers. Guest orders lack ownership verification, enabling attackers to access order details including billing address, customer information, and…
AplazadaMedia (5.3)0.11%—Paymob FOR WoocommerceAI23/9/202623/9/2026
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce orders as paid without any payment.
AplazadaMedia (4.3)0.15%—Wpswings Points AND Rewards FOR WoocommerceAI23/9/202623/9/2026
The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim handler, allowing authenticated users, Subscriber and above, to credit their own account with an arbitrary and unlimited amount of loyalty points and, where a…
AplazadaMedia (5.3)0.21%—Product Badge Label Countdown Timer FOR WoocommerceAI23/9/202623/9/2026
The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products.
AplazadaMedia (4.7)0.17%—Paymob FOR WoocommerceAI23/9/202623/9/2026
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX actions that manage its payment-gateway configuration, allowing users with contributor-level access to delete, wipe, or modify that configuration, including the stored payment credentials.
AplazadaMedia (5.3)0.20%—Paymob FOR WoocommerceAI23/9/202623/9/2026
The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers to write a card-token record to any user's account and to enumerate registered accounts.
AplazadaMedia (5.3)0.18%—Social Commerce FOR WoocommerceAI23/9/202623/9/2026
The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for WooCommerce WordPress plugin through 2.5.4 configuration and product synchronisation state.
AplazadaMedia (6.5)0.20%—Payment Plugins FOR Paypal WoocommerceAI23/9/202623/9/2026
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, allowing unauthenticated attackers to have another buyer's approved but uncaptured…
AplazadaAlta (7.3)0.40%—Magepeople Taxi Booking Manager FOR WoocommerceAI22/9/202622/9/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8.
AplazadaMedia (5.3)0.16%—Angelleye Payment Gateway FOR Paypal ON WoocommerceAI21/9/202622/9/2026
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own…
AplazadaMedia (4.3)0.35%—Partial Shipment FOR WoocommerceAI19/9/202621/9/2026
The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX actions. This is due to the AJAX handlers in woocommerce-partial-shipment.php (registered at lines…
AplazadaMedia (4.3)0.40%—Empik FOR WoocommerceAI19/9/202621/9/2026
The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above,…
AplazadaMedia (4.3)0.60%—Datalogics Ecommerce DeliveryAI19/9/202621/9/2026
The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.38%—WT Stripe Payment Gateway Stripe FOR WoocommerceAI19/9/202621/9/2026
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only…
AplazadaMedia (4.9)0.44%—Gopay FOR WoocommerceAI19/9/202621/9/2026
The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' parameter in all versions up to, and including, 1.0.36 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (5.3)0.23%—Ibtana Ecommerce Product AddonsAI19/9/202621/9/2026
The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaMedia (4.4)0.19%—OTP Login Register WoocommerceAI19/9/202621/9/2026
The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' Setting in all versions up to, and including, 2.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and…
AplazadaMedia (4.3)0.21%—PDF Builder FOR WoocommerceAI19/9/202621/9/2026
The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…
AplazadaMedia (5.3)0.30%—Mailchimp FOR WoocommerceAI19/9/202621/9/2026
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.
AplazadaMedia (5.3)0.33%—Rede Itau FOR WoocommerceAI19/9/202621/9/2026
The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying.
AplazadaAlta (8.6)0.45%—Price Drop Alert FOR WOO CommerceAI18/9/202618/9/2026
The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using them in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
AplazadaAlta (7.6)0.38%—MC Woocommerce WishlistAI17/9/202617/9/2026
Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.