Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
1872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.38% | — | Wpoperation Salert - Fake Sales Notification Woocommerce | 12/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPoperation SALERT – Fake Sales Notification WooCommerce plugin <= 1.2.1 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Wclovers Woocommerce Multivendor Marketplace | 9/6/2023 | 17/6/2026 | The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'get_item', 'get_order_notes' and 'add_order_note' functions in versions up to, and including, 1.5.3. This makes it possible for… | |
| Modificada | Crítica (9.8) | 43% | 💥 PoC | Tychesoftwares Abandoned Cart Lite FOR Woocommerce | 8/6/2023 | 17/6/2026 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode through the plugin. This allows unauthenticated attackers to log in as… | |
| Modificada | Media (6.5) | 0.80% | — | Villatheme Woocommerce Multi Currency | 7/6/2023 | 17/6/2026 | The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wmc_bulk_fixed_price function in versions up to, and including, 2.1.17. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to make changes to… | |
| Modificada | Alta (8.8) | 1.3% | — | Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+12 | 7/6/2023 | 17/6/2026 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or… | |
| Modificada | Media (4.3) | 0.60% | — | Palscode Woocommerce Multi Currency | 7/6/2023 | 17/6/2026 | El plugin WooCommerce Multi Currency para WordPress es vulnerable a una falta de autorización en versiones hasta la v2.1.17 inclusive. Esto hace posible que atacantes autenticados cambien el precio de un producto a un valor arbitrario. | |
| Modificada | Media (6.1) | 0.58% | — | Rightpress Woocommerce Dynamic Pricing AND Discounts | 7/6/2023 | 17/6/2026 | The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.1. This is due to missing sanitization on the settings imported via the import() function. This makes it possible for unauthenticated attackers to import a settings file… | |
| Modificada | Media (6.5) | 0.65% | — | Zorem Advanced Shipment Tracking FOR Woocommerce | 7/6/2023 | 17/6/2026 | The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5… | |
| Modificada | Alta (8.1) | 1.1% | — | Templateinvaders TI Woocommerce Wishlist | 7/6/2023 | 17/6/2026 | The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1.21.4 via the 'ti-woocommerce-wishlist/includes/export.class.php' file. This makes it possible for authenticated attackers to gain otherwise… | |
| Modificada | Alta (7.5) | 1.1% | — | Tychesoftwares Product Input Fields FOR Woocommerce | 7/6/2023 | 17/6/2026 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service. | |
| Modificada | Media (6.1) | 0.70% | — | Woocommerce Sidebar Manager TO Woosidebars Converter | 5/6/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in WooSidebars Sidebar Manager Converter Plugin up to 1.1.1 on WordPress. This affects the function process_request of the file classes/class-woosidebars-sbm-converter.php. The manipulation leads to open redirect. It is possible to initiate the attack… | |
| Modificada | Media (6.1) | 0.67% | — | Woocommerce Woosidebars | 5/6/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress. Affected by this issue is the function enable_custom_post_sidebars of the file classes/class-woo-sidebars.php. The manipulation of the argument sendback leads to open redirect. The attack may be… | |
| Modificada | Media (6.1) | 0.46% | — | Woocommerce Wooframework Tweaks | 5/6/2023 | 17/6/2026 | A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress. Affected by this vulnerability is the function admin_screen_logic of the file wooframework-tweaks.php. The manipulation of the argument url leads to open redirect. The attack can be launched remotely. Upgrading… | |
| Modificada | Media (6.1) | 0.66% | — | Woocommerce Wooframework Branding | 5/6/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_screen_logic of the file wooframework-branding.php. The manipulation of the argument url leads to open redirect. It is possible to launch the attack remotely. Upgrading to… | |
| Modificada | Crítica (9.8) | 1.2% | — | Wisetr User Email Verification FOR Woocommerce | 3/6/2023 | 17/6/2026 | The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation weakness in the resend_verification_email function. This allows unauthenticated attackers to… | |
| Modificada | Media (6.1) | 0.95% | 💥 Exploit | Themeisle Product Addons & Fields FOR Woocommerce | 30/5/2023 | 17/6/2026 | The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting. | |
| Modificada | Alta (8.8) | 0.26% | — | Codeixer Product Gallery Slider FOR Woocommerce | 29/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Codeixer Product Gallery Slider for WooCommerce plugin <= 2.2.8 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Woocommerce Product Vendors Project Woocommerce Product Vendors | 28/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Product Vendors plugin <= 2.1.76 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Woocommerce Automatewoo | 28/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Woocommerce Automatewoo | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions. | |
| Modificada | Alta (8.8) | 0.30% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager Professional | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Gvectors Woodiscuz - Woocommerce Comments | 28/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments woodiscuz-woocommerce-comments allows Stored XSS.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.2.9. | |
| Modificada | Alta (8.8) | 0.26% | — | Orion Woocommerce Products Designer | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ORION Woocommerce Products Designer plugin <= 4.3.3 versions. | |
| Modificada | Alta (8.8) | 0.23% | — | Villatheme Woocommerce Thank YOU Page Customizer | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Thank You Page Customizer for WooCommerce – Increase Your Sales plugin <= 1.0.13 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Tychesoftwares Custom Order Numbers FOR Woocommerce | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Custom Order Numbers for WooCommerce plugin <= 1.4.0 versions. |