Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1856 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.40% | — | Empik FOR WoocommerceAI | 19/9/2026 | 21/9/2026 | The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Aplazada | Media (5.3) | 0.38% | — | WT Stripe Payment Gateway Stripe FOR WoocommerceAI | 19/9/2026 | 21/9/2026 | The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only… | |
| Aplazada | Media (4.9) | 0.44% | — | Gopay FOR WoocommerceAI | 19/9/2026 | 21/9/2026 | The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' parameter in all versions up to, and including, 1.0.36 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (4.4) | 0.19% | — | OTP Login Register WoocommerceAI | 19/9/2026 | 21/9/2026 | The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' Setting in all versions up to, and including, 2.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and… | |
| Aplazada | Media (4.3) | 0.21% | — | PDF Builder FOR WoocommerceAI | 19/9/2026 | 21/9/2026 | The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.30% | — | Mailchimp FOR WoocommerceAI | 19/9/2026 | 21/9/2026 | The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change. | |
| Aplazada | Media (5.3) | 0.33% | — | Rede Itau FOR WoocommerceAI | 19/9/2026 | 21/9/2026 | The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a pending order as paid without paying. | |
| Aplazada | Alta (7.6) | 0.38% | — | MC Woocommerce WishlistAI | 17/9/2026 | 17/9/2026 | Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. | |
| Aplazada | Baja (3.7) | 0.14% | — | Robokassa Payment Gateway FOR WoocommerceAI | 17/9/2026 | 18/9/2026 | The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold… | |
| Aplazada | Media (4.3) | 0.14% | — | Active Woot Products Tables FOR WoocommerceAI | 17/9/2026 | 18/9/2026 | The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title of arbitrary posts, pages and products. | |
| Aplazada | Baja (3.7) | 0.26% | — | Event Booking Manager FOR WoocommerceAI | 17/9/2026 | 18/9/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom… | |
| Aplazada | Media (4.3) | 0.17% | — | Subscriptions FOR WoocommerceAI | 16/9/2026 | 17/9/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a crafted request they are tricked into making. | |
| Aplazada | Media (5.3) | 0.34% | — | Subscriptions FOR WoocommerceAI | 16/9/2026 | 17/9/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to retrieve the store's full list of subscriptions, including customer usernames, product names, recurring amounts and payment dates. | |
| Aplazada | Media (5.3) | 0.39% | — | NI Woocommerce Sales ReportAI | 16/9/2026 | 17/9/2026 | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's… | |
| Aplazada | Alta (8.6) | 0.45% | — | NI Woocommerce Sales ReportAI | 16/9/2026 | 17/9/2026 | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. | |
| Aplazada | Media (5.3) | 0.29% | — | Deposits AND Partial Payments FOR WoocommerceAI | 11/9/2026 | 11/9/2026 | Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions. | |
| Aplazada | Media (5.3) | 0.30% | — | Moreconvert Woocommerce WishlistAI | 11/9/2026 | 11/9/2026 | The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Mipl Grouped Checkout Fields FOR WoocommerceAI | 11/9/2026 | 11/9/2026 | The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.1) | 0.37% | — | Themify Woocommerce Product FilterAI | 11/9/2026 | 11/9/2026 | The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.32% | — | OTP Login Register WoocommerceAI | 11/9/2026 | 11/9/2026 | The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `process_otp_form` is keyed exclusively on the attacker-controlled… | |
| Aplazada | Alta (7.5) | 0.35% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions. | |
| Aplazada | Alta (8.6) | 0.53% | — | Studiowombat Advanced Product Fields Extended FOR WoocommerceAI | 10/9/2026 | 11/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6. | |
| Aplazada | Alta (7.5) | 0.39% | — | Thank YOU Page Customizer FOR WoocommerceAI | 10/9/2026 | 11/9/2026 | Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Robokassa Payment Gateway FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions. | |
| Aplazada | Alta (7.2) | 0.46% | — | Registration Form FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-controlled post instead. A user able to create a post (Contributor and above) can… |