Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

1856 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.40%—Empik FOR WoocommerceAI19/9/202621/9/2026
The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above,…
AplazadaMedia (5.3)0.38%—WT Stripe Payment Gateway Stripe FOR WoocommerceAI19/9/202621/9/2026
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only…
AplazadaMedia (4.9)0.44%—Gopay FOR WoocommerceAI19/9/202621/9/2026
The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' parameter in all versions up to, and including, 1.0.36 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (4.4)0.19%—OTP Login Register WoocommerceAI19/9/202621/9/2026
The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' Setting in all versions up to, and including, 2.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and…
AplazadaMedia (4.3)0.21%—PDF Builder FOR WoocommerceAI19/9/202621/9/2026
The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…
AplazadaMedia (5.3)0.30%—Mailchimp FOR WoocommerceAI19/9/202621/9/2026
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.
AplazadaMedia (5.3)0.33%—Rede Itau FOR WoocommerceAI19/9/202621/9/2026
The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying.
AplazadaAlta (7.6)0.38%—MC Woocommerce WishlistAI17/9/202617/9/2026
Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
AplazadaBaja (3.7)0.14%—Robokassa Payment Gateway FOR WoocommerceAI17/9/202618/9/2026
The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold…
AplazadaMedia (4.3)0.14%—Active Woot Products Tables FOR WoocommerceAI17/9/202618/9/2026
The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title of arbitrary posts, pages and products.
AplazadaBaja (3.7)0.26%—Event Booking Manager FOR WoocommerceAI17/9/202618/9/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom…
AplazadaMedia (4.3)0.17%—Subscriptions FOR WoocommerceAI16/9/202617/9/2026
The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a crafted request they are tricked into making.
AplazadaMedia (5.3)0.34%—Subscriptions FOR WoocommerceAI16/9/202617/9/2026
The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to retrieve the store's full list of subscriptions, including customer usernames, product names, recurring amounts and payment dates.
AplazadaMedia (5.3)0.39%—NI Woocommerce Sales ReportAI16/9/202617/9/2026
The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's…
AplazadaAlta (8.6)0.45%—NI Woocommerce Sales ReportAI16/9/202617/9/2026
The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.
AplazadaMedia (5.3)0.29%—Deposits AND Partial Payments FOR WoocommerceAI11/9/202611/9/2026
Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.
AplazadaMedia (5.3)0.30%—Moreconvert Woocommerce WishlistAI11/9/202611/9/2026
The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.
AplazadaCrítica (9.8)1.1%—Mipl Grouped Checkout Fields FOR WoocommerceAI11/9/202611/9/2026
The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated…
AplazadaMedia (6.1)0.37%—Themify Woocommerce Product FilterAI11/9/202611/9/2026
The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (5.3)0.32%—OTP Login Register WoocommerceAI11/9/202611/9/2026
The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `process_otp_form` is keyed exclusively on the attacker-controlled…
AplazadaAlta (7.5)0.35%—Wpswings Return Refund AND Exchange FOR WoocommerceAI10/9/202610/9/2026
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.
AplazadaAlta (8.6)0.53%—Studiowombat Advanced Product Fields Extended FOR WoocommerceAI10/9/202611/9/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6.
AplazadaAlta (7.5)0.39%—Thank YOU Page Customizer FOR WoocommerceAI10/9/202611/9/2026
Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions.
AplazadaMedia (6.5)0.33%—Robokassa Payment Gateway FOR WoocommerceAI10/9/202610/9/2026
Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.
AplazadaAlta (7.2)0.46%—Registration Form FOR WoocommerceAI10/9/202610/9/2026
The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-controlled post instead. A user able to create a post (Contributor and above) can…