Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1856 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.36% | — | Woocart Suggestion Engine FOR WoocommerceAI | 27/8/2026 | 28/8/2026 | Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Music Player FOR WoocommerceAI | 27/8/2026 | 28/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. | |
| Aplazada | Alta (8.6) | 0.36% | — | Mobile APP FOR WoocommerceAI | 27/8/2026 | 28/8/2026 | Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Woocommerce LotteryAI | 26/8/2026 | 26/8/2026 | The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Media (6.5) | 0.27% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 26/8/2026 | 26/8/2026 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return… | |
| Aplazada | Alta (8.6) | 0.53% | — | Woocommerce File ApprovalAI | 24/8/2026 | 24/8/2026 | Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. | |
| Aplazada | Media (4.3) | 0.28% | — | Woocommerce BookingsAI | 23/8/2026 | 26/8/2026 | The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products. | |
| Aplazada | Media (6.5) | 0.87% | — | Webtoffee Woocommerce PDF Invoices Packing Slips Delivery Notes Shipping LabelsAI | 23/8/2026 | 24/8/2026 | The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Crítica (9.8) | 0.71% | — | Automation WEB Platform Notifications AND OTP FOR WoocommerceAI | 21/8/2026 | 24/8/2026 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly… | |
| Aplazada | Alta (7.1) | 0.25% | — | Paymob FOR WoocommerceAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Swatchly - Woocommerce Variation Swatches FOR ProductsAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Yith Woocommerce Membership PremiumAI | 19/8/2026 | 20/8/2026 | Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. | |
| Aplazada | Media (5.3) | 0.32% | — | Wpswings Membership FOR WoocommerceAI | 19/8/2026 | 26/8/2026 | The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the… | |
| Aplazada | Media (5.3) | 0.29% | — | Razorpay FOR WoocommerceAI | 18/8/2026 | 20/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. | |
| Aplazada | Media (6.5) | 0.42% | — | Flutterwave WoocommerceAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. | |
| Aplazada | Media (6.5) | 0.42% | — | Piraeus Bank Woocommerce Payment GatewayAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. | |
| Aplazada | Alta (7.1) | 0.40% | — | MWB Hubspot FOR WoocommerceAI | 18/8/2026 | 20/8/2026 | Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. | |
| Aplazada | Alta (7.1) | 0.29% | — | Wpexperts License Manager FOR WoocommerceAI | 18/8/2026 | 20/8/2026 | Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. | |
| Aplazada | Alta (7.5) | 0.50% | — | Webtoffee Extra Product Options AND ADD ONS FOR WoocommerceAI | 18/8/2026 | 20/8/2026 | Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions. | |
| Aplazada | Alta (7.5) | 0.45% | — | Webtoffee Extra Product Options Builder FOR WoocommerceAI | 16/8/2026 | 26/8/2026 | The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product Options Builder for WooCommerce WordPress… | |
| Aplazada | Media (5.9) | 0.29% | — | Epeken ALL Kurir FOR WoocommerceAI | 14/8/2026 | 31/8/2026 | The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-confirmation request originates from the owner of the targeted order, nor that any payment actually occurred, allowing unauthenticated attackers to mark arbitrary orders as confirmed and, in a non-default configuration,… | |
| Aplazada | Alta (8.6) | 0.45% | — | Paymob FOR WoocommerceAI | 14/8/2026 | 26/8/2026 | The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to… | |
| Aplazada | Alta (7.1) | 0.26% | — | Snstheme Samex Clean Minimal Shop Woocommerce Wordpress ThemeAISnstheme M ANH Fashion Woocommerce Wordpress ThemeAI | 13/8/2026 | 14/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress… | |
| Aplazada | Media (5.3) | 0.31% | — | Revolut Gateway FOR WoocommerceAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. | |
| Aplazada | Alta (7.6) | 0.38% | — | Mailchimp FOR WoocommerceAI | 13/8/2026 | 14/8/2026 | Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. |