Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

1856 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.36%—Woocart Suggestion Engine FOR WoocommerceAI27/8/202628/8/2026
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
AplazadaAlta (7.1)0.25%—Music Player FOR WoocommerceAI27/8/202628/8/2026
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
AplazadaAlta (8.6)0.36%—Mobile APP FOR WoocommerceAI27/8/202628/8/2026
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
AplazadaAlta (7.5)0.32%—Woocommerce LotteryAI26/8/202626/8/2026
The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
AplazadaMedia (6.5)0.27%—Wpswings Return Refund AND Exchange FOR WoocommerceAI26/8/202626/8/2026
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return…
AplazadaAlta (8.6)0.53%—Woocommerce File ApprovalAI24/8/202624/8/2026
Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
AplazadaMedia (4.3)0.28%—Woocommerce BookingsAI23/8/202626/8/2026
The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.
AplazadaMedia (6.5)0.87%—Webtoffee Woocommerce PDF Invoices Packing Slips Delivery Notes Shipping LabelsAI23/8/202624/8/2026
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaCrítica (9.8)0.71%—Automation WEB Platform Notifications AND OTP FOR WoocommerceAI21/8/202624/8/2026
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly…
AplazadaAlta (7.1)0.25%—Paymob FOR WoocommerceAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
AplazadaAlta (7.1)0.25%—Swatchly - Woocommerce Variation Swatches FOR ProductsAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.
AplazadaAlta (8.5)0.36%—Yith Woocommerce Membership PremiumAI19/8/202620/8/2026
Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
AplazadaMedia (5.3)0.32%—Wpswings Membership FOR WoocommerceAI19/8/202626/8/2026
The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the…
AplazadaMedia (5.3)0.29%—Razorpay FOR WoocommerceAI18/8/202620/8/2026
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
AplazadaMedia (6.5)0.42%—Flutterwave WoocommerceAI18/8/202620/8/2026
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
AplazadaMedia (6.5)0.42%—Piraeus Bank Woocommerce Payment GatewayAI18/8/202620/8/2026
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
AplazadaAlta (7.1)0.40%—MWB Hubspot FOR WoocommerceAI18/8/202620/8/2026
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
AplazadaAlta (7.1)0.29%—Wpexperts License Manager FOR WoocommerceAI18/8/202620/8/2026
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
AplazadaAlta (7.5)0.50%—Webtoffee Extra Product Options AND ADD ONS FOR WoocommerceAI18/8/202620/8/2026
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
AplazadaAlta (7.5)0.45%—Webtoffee Extra Product Options Builder FOR WoocommerceAI16/8/202626/8/2026
The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product Options Builder for WooCommerce WordPress…
AplazadaMedia (5.9)0.29%—Epeken ALL Kurir FOR WoocommerceAI14/8/202631/8/2026
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration,…
AplazadaAlta (8.6)0.45%—Paymob FOR WoocommerceAI14/8/202626/8/2026
The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to…
AplazadaAlta (7.1)0.26%—Snstheme Samex Clean Minimal Shop Woocommerce Wordpress ThemeAISnstheme M ANH Fashion Woocommerce Wordpress ThemeAI13/8/202614/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress…
AplazadaMedia (5.3)0.31%—Revolut Gateway FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
AplazadaAlta (7.6)0.38%—Mailchimp FOR WoocommerceAI13/8/202614/8/2026
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.