Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
133 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.52% | — | Noorsplugin WP Stripe Checkout | 5/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Naa986 WP Stripe Checkout.This issue affects WP Stripe Checkout: from n/a through 1.2.2.37. | |
| Modificada | Crítica (9.8) | 0.57% | — | Mestresdowp Checkout Mestres WP | 31/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestres do WP Checkout Mestres WP.This issue affects Checkout Mestres WP: from n/a through 7.1.9.6. | |
| Modificada | Media (6.1) | 0.47% | — | Levantoan Woocommerce Vietnam Checkout | 27/11/2023 | 17/6/2026 | The Woocommerce Vietnam Checkout WordPress plugin before 2.0.6 does not escape the custom shipping phone field no the checkout form leading to XSS | |
| Modificada | Crítica (9.8) | 0.58% | — | Knowband Supercheckout | 19/10/2023 | 17/6/2026 | KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the module "Module One Page Checkout, Social Login & Mailchimp" (supercheckout), a guest can upload files with extensions .php | |
| Modificada | Crítica (9.8) | 0.95% | — | Knowband ONE Page Checkout, Social Login & Mailchimp | 5/10/2023 | 17/6/2026 | SQL injection vulnerability in KnowBand Module One Page Checkout, Social Login & Mailchimp (supercheckout) v.8.0.3 and before allows a remote attacker to execute arbitrary code via a crafted request to the updateCheckoutBehaviour function in the supercheckout.php component. | |
| Modificada | Alta (8.8) | 0.25% | — | Plainviewplugins Mycryptocheckout | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in edward_plainview MyCryptoCheckout plugin <= 2.125 versions. | |
| Modificada | Media (6.5) | 0.32% | — | Addify Abandoned Cart RecoveryAddify Advanced Free GiftsAddify Checkout Fields ManagerAddify Custom Fields FOR Woocommerce+6 | 31/7/2023 | 17/6/2026 | The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through 1.0.1, Custom Registration Forms Builder WordPress plugin before 1.0.2, Advanced Free Gifts… | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Add-to-cart-direct-checkout-for-woocommerce | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Direct checkout, Add to cart redirect, Quick purchase button, Buy now button, Quick View button for WooCommerce plugin <= 2.1.48 versions. | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | Wpdesk Flexible Checkout Fields | 7/6/2023 | 17/6/2026 | The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to missing authorization checks on the updateSettingsAction() function which is called via… | |
| Modificada | Media (6.1) | 0.38% | — | Woocommerce Custom Checkout Fields Editor With Drag & Drop Project Woocommerce Custom Checkout Fields Editor With Drag & Drop | 9/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Umair Saleem Woocommerce Custom Checkout Fields Editor With Drag & Drop plugin <= 0.1 versions. | |
| Modificada | Media (6.1) | 0.85% | 💥 Exploit | Plainviewplugins Mycryptocheckout | 2/5/2023 | 17/6/2026 | The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.41% | — | Levantoan Woocommerce Vietnam Checkout | 27/3/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Le Van Toan Woocommerce Vietnam Checkout plugin <= 2.0.4 versions. | |
| Modificada | Media (4.8) | 0.35% | — | Tipsandtricks-hq WP Express Checkout | 17/3/2023 | 17/6/2026 | The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pec_coupon[code]’ parameter in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access to inject… | |
| Modificada | Crítica (9.8) | 4.4% | 💥 Exploit | Najeebmedia Woocommerce Checkout Field Manager | 6/3/2023 | 17/6/2026 | The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server | |
| Modificada | Media (4.3) | 0.23% | — | Checkoutplugins Stripe Payments FOR Woocommerce | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce plugin <= 1.4.10 leads to settings change. | |
| Modificada | Media (5.4) | 0.48% | — | Noorsplugin WP Stripe Checkout | 19/12/2022 | 17/6/2026 | The WP Stripe Checkout WordPress plugin before 1.2.2.21 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.48% | — | Noorsplugin Checkout FOR Paypal | 19/12/2022 | 17/6/2026 | The Checkout for PayPal WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (7.2) | 1.2% | — | Themehigh Checkout Field Editor FOR Woocommerce | 28/11/2022 | 17/6/2026 | The Checkout Field Editor (Checkout Manager) for WooCommerce WordPress plugin before 1.8.0 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Checkout | 7/10/2022 | 17/6/2026 | Improper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive information via implicit intent broadcast. | |
| Modificada | Media (5.5) | 0.26% | — | Samsung Checkout | 5/8/2022 | 17/6/2026 | SQL injection vulnerability via IAPService in Samsung Checkout prior to version 5.0.53.1 allows attackers to access IAP information. | |
| Modificada | Media (6.1) | 0.70% | — | Wpwham Checkout Files Upload FOR Woocommerce | 20/5/2022 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in WP Wham's Checkout Files Upload for WooCommerce plugin <= 2.1.2 at WordPress. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Media (5.3) | 1.1% | — | Woocommerce Paypal Checkout Payment Gateway | 29/8/2019 | 17/6/2026 | cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be… | |
| Modificada | Media (6.1) | 0.95% | — | Ithemes 2checkout | 28/8/2019 | 17/6/2026 | 2Checkout Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |
| Modificada | Alta (7.5) | 1.5% | — | Visser Woocommerce Checkout Manager | 6/5/2019 | 17/6/2026 | The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks. |