Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

1856 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.45%—Zipmoney Payments FOR WoocommerceAI10/9/202610/9/2026
The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary WordPress options. This can be used to…
AplazadaAlta (7.5)0.26%—Wpswings Ultimate Gift Cards FOR WoocommerceAI10/9/202610/9/2026
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption…
AplazadaAlta (7.5)0.68%—Direct Download FOR WoocommerceAI10/9/202610/9/2026
The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive…
AplazadaAlta (8.8)0.24%—Yith Woocommerce WaitlistAI9/9/20269/9/2026
The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.35.0. This is due to the add_user_in_waiting_list() function registered on the wp_ajax_yith_wcwtl_add_user action being missing both a capability check and a nonce verification, and…
AplazadaMedia (6.5)0.26%—Wpmr Google Feed Manager FOR WoocommerceAI9/9/20269/9/2026
The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnerable to time-based SQL Injection via the 'feed' parameter in all versions up to, and including, 2.23.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
AplazadaMedia (4.3)0.43%—Checkout Custom Fields Builder FOR WoocommerceAI9/9/20269/9/2026
The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.3)0.34%—Reviso Exporter FOR WoocommerceAI9/9/202611/9/2026
The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the disconnect_callback() function in versions up to, and including, 1.2.3. The function is registered to the 'wp_ajax_wcefr-disconnect' AJAX…
AplazadaMedia (5.9)0.23%—Paymentplugins Payment Plugins FOR Paypal WoocommerceAI9/9/20269/9/2026
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's stored card to their own account and then charge or delete it. Exploitation requires…
AplazadaMedia (5.3)0.34%—Payment Plugins FOR Paypal WoocommerceAI9/9/20269/9/2026
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the secret that gates access to any order and, through it, that customer's billing and…
AplazadaAlta (8.1)0.90%—Next Cart Store TO Woocommerce MigrationAI9/9/20269/9/2026
The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/next_cart/v1/migration` REST route with `permission_callback` set to…
AplazadaAlta (8.6)0.40%—Elex Woocommerce Request A QuoteAI9/9/20269/9/2026
The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary data from the database.
AplazadaMedia (6.1)0.46%—WBW Product Filter FOR WoocommerceAI9/9/20269/9/2026
The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpf_fid' parameter in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (7.5)0.35%—Visztpeter Csomagpontok ES Szallitasi Cimkek Woocommerce-hezAI8/9/20268/9/2026
Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási címkék WooCommerce-hez: from n/a before 4.2.8.
AplazadaAlta (7.5)0.46%—Automattic WoocommerceAI8/9/20268/9/2026
Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.
AplazadaMedia (6.5)0.33%—Multivendorx Product Catalog Enquiry FOR WoocommerceAI8/9/20267/10/2026
Incorrect Privilege Assignment vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX woocommerce-catalog-enquiry allows Privilege Escalation.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 6.1.5.
AplazadaAlta (7.6)0.40%—Automattic WoocommerceAI4/9/20264/9/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL Injection. This issue affects WooCommerce: from n/a before 11.0.
AplazadaMedia (6.5)0.29%—Flycart Pre-orders FOR WoocommerceAI3/9/20263/9/2026
Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.
AplazadaCrítica (9.8)0.48%—Yith Request A Quote FOR WoocommerceAI3/9/20267/9/2026
Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
AplazadaMedia (6.5)0.22%—Product Variations Swatches FOR WoocommerceAI3/9/20264/9/2026
Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.
AplazadaMedia (5.3)0.31%—Wpswings Ultimate Gift Cards FOR WoocommerceAI2/9/20262/9/2026
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
AplazadaAlta (7.5)0.42%—Appchee Woocommerce Product AttachmentAI2/9/20262/9/2026
Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.
AplazadaAlta (7.1)0.25%—Upsell Order Bump Offer FOR WoocommerceAI2/9/20262/9/2026
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
AplazadaAlta (8.8)0.51%—Cusrev Customer Reviews FOR WoocommerceAI30/8/202631/8/2026
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
AplazadaCrítica (9.8)0.40%—Custom User Registration Fields FOR WoocommerceAI29/8/20261/9/2026
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in…
AplazadaAlta (7.2)0.42%—Cusrev Customer Reviews FOR WoocommerceAI28/8/202628/8/2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review comment text. The plugin accepts review…