Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

1856 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Multiparcels Shipping FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.
AplazadaAlta (7.1)0.25%—Local Delivery Drivers FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.
AplazadaAlta (7.5)0.35%—Storegrowth Smart Sales Booster FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.
AplazadaAlta (7.5)0.42%—Woocommerce AppointmentsAI13/8/202614/8/2026
Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
AplazadaAlta (7.5)0.35%—Smepay UPI Gateway FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
AplazadaCrítica (9.8)0.50%—Wpfactory Customer Email Verification FOR WoocommerceAI13/8/202626/8/2026
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered…
AplazadaMedia (5.3)0.16%—Paypal Payment Gateway FOR WoocommerceAI12/8/202626/8/2026
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the…
AplazadaMedia (6.5)0.34%—Wpswings Wallet System FOR WoocommerceAI12/8/202626/8/2026
The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero, and complete checkout without paying the…
AplazadaMedia (5.3)0.34%—Order Sync With Zendesk FOR WoocommerceAI12/8/202626/8/2026
The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer…
AplazadaCrítica (9.8)0.96%—Woocommerce SubscriptionsAI12/8/202626/8/2026
The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a gadget chain present in the bundled…
AplazadaCrítica (9.1)0.40%—Wallet FOR WoocommerceAI12/8/202626/8/2026
The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers to top up their wallet balance for less than its value.
AplazadaCrítica (9.8)0.83%💥 PoCTychesoftwares Product Input Fields FOR WoocommerceAI10/8/202626/8/2026
The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on…
AplazadaBaja (3.7)0.24%—Accept Paypal Stripe With Subscriptions FOR WoocommerceAI10/8/202626/8/2026
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal…
AplazadaMedia (5.3)0.29%—Accept Paypal Stripe With Subscriptions FOR WoocommerceAI10/8/202626/8/2026
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full…
AplazadaMedia (5.4)0.23%—Cusrev Customer Reviews FOR WoocommerceAI10/8/202626/8/2026
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin…
AplazadaMedia (5.9)0.16%—Subscriptions FOR WoocommerceAI7/8/202626/8/2026
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without…
AplazadaAlta (8.8)0.64%—Subscriptions FOR WoocommerceAI7/8/202626/8/2026
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack…
AplazadaMedia (4.3)0.27%—Subscriptions FOR WoocommerceAI7/8/202626/8/2026
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that…
AplazadaMedia (5.3)0.32%—Event Booking Manager FOR WoocommerceAI6/8/202626/8/2026
The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to…
AplazadaAlta (7.5)0.19%—Redyx Payment Gateway FOR Redsys AND Woocommerce LiteAI6/8/202626/8/2026
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own…
AplazadaAlta (7.5)0.21%—Integrate Phonepe With WoocommerceAI6/8/202626/8/2026
The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark…
AplazadaAlta (7.1)0.25%—Wpml Woocommerce Multilingual AND MulticurrencyAI6/8/202612/8/2026
Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
AplazadaAlta (7.1)0.25%—Facebook FOR WoocommerceAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
AplazadaMedia (5.3)0.31%—Mercadopago Mercado Pago Payments FOR WoocommerceAI6/8/202612/8/2026
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
AplazadaMedia (5.3)0.33%—Yithemes Yith Woocommerce Zoom MagnifierAI6/8/202612/8/2026
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.