Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
3237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.68% | — | Direct Download FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Aplazada | Alta (8.8) | 0.24% | — | Yith Woocommerce WaitlistAI | 9/9/2026 | 9/9/2026 | The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.35.0. This is due to the add_user_in_waiting_list() function registered on the wp_ajax_yith_wcwtl_add_user action being missing both a capability check and a nonce verification, and… | |
| Aplazada | Media (6.5) | 0.26% | — | Wpmr Google Feed Manager FOR WoocommerceAI | 9/9/2026 | 9/9/2026 | The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnerable to time-based SQL Injection via the 'feed' parameter in all versions up to, and including, 2.23.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Aplazada | Media (4.3) | 0.43% | — | Checkout Custom Fields Builder FOR WoocommerceAI | 9/9/2026 | 9/9/2026 | The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.34% | — | Reviso Exporter FOR WoocommerceAI | 9/9/2026 | 11/9/2026 | The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the disconnect_callback() function in versions up to, and including, 1.2.3. The function is registered to the 'wp_ajax_wcefr-disconnect' AJAX… | |
| Aplazada | Media (5.9) | 0.23% | — | Paymentplugins Payment Plugins FOR Paypal WoocommerceAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's stored card to their own account and then charge or delete it. Exploitation requires… | |
| Aplazada | Media (5.3) | 0.34% | — | Payment Plugins FOR Paypal WoocommerceAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the secret that gates access to any order and, through it, that customer's billing and… | |
| Aplazada | Alta (8.1) | 0.90% | — | Next Cart Store TO Woocommerce MigrationAI | 9/9/2026 | 9/9/2026 | The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/next_cart/v1/migration` REST route with `permission_callback` set to… | |
| Aplazada | Alta (8.6) | 0.40% | — | Elex Woocommerce Request A QuoteAI | 9/9/2026 | 9/9/2026 | The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary data from the database. | |
| Aplazada | Media (6.1) | 0.46% | — | WBW Product Filter FOR WoocommerceAI | 9/9/2026 | 9/9/2026 | The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpf_fid' parameter in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Alta (8.6) | 0.83% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 9/9/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Alta (8.7) | 0.84% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 11/9/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this… | |
| Analizada | Alta (7.6) | 1.1% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 10/9/2026 | Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions,… | |
| Analizada | Alta (8.6) | 0.69% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 9/9/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Alta (7.5) | 0.82% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 11/9/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction. | |
| Analizada | Alta (8.2) | 0.67% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 10/9/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction. | |
| Analizada | Crítica (9.3) | 0.74% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 9/9/2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… | |
| Analizada | Crítica (9.3) | 0.74% | — | Adobe MagentoAdobe CommerceAdobe Commerce B2B | 8/9/2026 | 9/9/2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… | |
| Aplazada | Alta (7.5) | 0.35% | — | Visztpeter Csomagpontok ES Szallitasi Cimkek Woocommerce-hezAI | 8/9/2026 | 8/9/2026 | Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási címkék WooCommerce-hez: from n/a before 4.2.8. | |
| Aplazada | Alta (7.5) | 0.46% | — | Automattic WoocommerceAI | 8/9/2026 | 8/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0. | |
| Aplazada | Media (6.5) | 0.33% | — | Multivendorx Product Catalog Enquiry FOR WoocommerceAI | 8/9/2026 | 7/10/2026 | Incorrect Privilege Assignment vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX woocommerce-catalog-enquiry allows Privilege Escalation.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 6.1.5. | |
| Analizada | Crítica (10) | 3.9% | ⚠ Explotación activa💥 PoC | Adobe CommerceAdobe Commerce B2BAdobe Magento | 7/9/2026 | 9/9/2026 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user… | |
| Aplazada | Alta (7.6) | 0.40% | — | Automattic WoocommerceAI | 4/9/2026 | 4/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL Injection. This issue affects WooCommerce: from n/a before 11.0. | |
| Aplazada | Media (6.5) | 0.29% | — | Flycart Pre-orders FOR WoocommerceAI | 3/9/2026 | 3/9/2026 | Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Yith Request A Quote FOR WoocommerceAI | 3/9/2026 | 7/9/2026 | Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. |