Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2840▲ 88 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.38% | — | Pluginforage Woocommerce Product Categories Selection Widget | 25/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PluginForage WooCommerce Product Categories Selection Widget plugin <= 2.0 versions. | |
| Modificada | Media (5.4) | 0.33% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 18/7/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Woocommerce Shipping Multiple Addresses | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Shipping Multiple Addresses plugin <= 3.8.5 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Woocommerce Automatewoo | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.5 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Woocommerce Order Barcodes | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Order Barcodes plugin <= 1.6.4 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Hasthemes Woolentor - Woocommerce Elementor Addons + Builder | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.6.2 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Woocommerce Brands | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Brands plugin <= 1.6.49 versions. | |
| Modificada | Alta (8.8) | 0.39% | — | Gsheetconnector Woocommerce Google Sheet Connector | 17/7/2023 | 17/6/2026 | The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Modificada | Alta (7.5) | 0.77% | — | Getnet Argentina Para Woocommerce Project Getnet Argentina Para Woocommerce | 12/7/2023 | 17/6/2026 | The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment. | |
| Modificada | Media (4.3) | 0.38% | — | Tychesoftwares Abandoned Cart Lite FOR Woocommerce | 12/7/2023 | 17/6/2026 | El plugin Abandoned Cart Lite for WooCommerce para WordPress es vulnerable a ataques de tipo Cross-Site Request Forgery en versiones hasta la 5.8.5 inclusive. Esto es debido a la falta o incorrecta validación nonce en la función "wcal_preview_emails()". Esto hace posible que los atacantes no autenticados generen… | |
| Modificada | Media (4.3) | 0.38% | — | Exportfeed Woocommerce Etsy Integration | 12/7/2023 | 17/6/2026 | The WooCommerce Etsy Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.1. This is due to missing or incorrect nonce validation on the etcpf_delete_feed() function. This makes it possible for unauthenticated attackers to delete an export feed via a forged… | |
| Modificada | Alta (8.8) | 0.27% | — | Storeapps Stock Manager FOR Woocommerce | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in StoreApps Stock Manager for WooCommerce plugin <= 2.10.0 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Piwebsolution Advanced-free-flat-shipping-woocommerce | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PI Websolution Conditional shipping & Advanced Flat rate shipping rates / Flexible shipping for WooCommerce shipping plugin <= 1.6.4.4 versions. | |
| Modificada | Alta (8.8) | 0.34% | — | Wpzone Potent Donations FOR Woocommerce | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Zone Potent Donations for WooCommerce plugin <= 1.1.9 versions. | |
| Modificada | Media (6.5) | 0.43% | — | Villatheme Abandoned Cart Recovery FOR Woocommerce | 1/7/2023 | 17/6/2026 | The Abandoned Cart Recovery for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the get_items() and extra_tablenav() functions. This makes it possible for unauthenticated attackers to perform… | |
| Modificada | Media (4.3) | 0.48% | — | Wpswings Ultimate Gift Cards FOR Woocommerce | 1/7/2023 | 17/6/2026 | The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the mwb_wgm_save_post() function. This makes it possible for unauthenticated attackers to modify product gift card… | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Cancel Order Request / Return Order / Repeat Order / Reorder FOR Woocommerce | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Cancel order request / Return order / Repeat Order / Reorder for WooCommerce plugin <= 1.3.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Conditional Cart FEE / Extra Charge Rule FOR Woocommerce Extra Fees | 26/6/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PI Websolution Conditional cart fee plugin <= 1.0.96 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Pi-woocommerce-order-date-time-and-type | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Order date, Order pickup, Order date time, Pickup Location, delivery date for WooCommerce plugin <= 3.0.19 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Add-to-cart-direct-checkout-for-woocommerce | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Direct checkout, Add to cart redirect, Quick purchase button, Buy now button, Quick View button for WooCommerce plugin <= 2.1.48 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Wpovernight Download Quick/bulk Order Form FOR Woocommerce | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Overnight Quick/Bulk Order Form for WooCommerce plugin <= 3.5.7 versions. | |
| Modificada | Media (6.1) | 0.42% | — | Woocommerce Bulk Stock Management | 22/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Bulk Stock Management plugin <= 2.2.33 versions. | |
| Modificada | Alta (8.8) | 0.29% | — | Woocommerce Paypal Payments | 22/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Tychesoftwares Abandoned Cart Lite FOR WoocommerceTychesoftwares Abandoned Cart PRO FOR Woocommerce | 22/6/2023 | 17/6/2026 | The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping. This makes it possible… | |
| Modificada | Alta (7.5) | 1.2% | — | Woocommerce Stripe Payment Gateway | 14/6/2023 | 17/6/2026 | Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions. |