Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
1872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.29% | — | Mage-people Event Manager AND Tickets Selling Plugin FOR Woocommerce | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.7.7 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Villatheme Woocommerce Thank YOU Page Customizer | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Thank You Page Customizer for WooCommerce – Increase Your Sales plugin <= 1.0.13 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Zorem Advanced Shipment Tracking FOR Woocommerce | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Zorem Advanced Shipment Tracking for WooCommerce plugin <= 3.5.2 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Weightbasedshipping Woocommerce Weight Based Shipping | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in weightbasedshipping.Com WooCommerce Weight Based Shipping plugin <= 5.4.1 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | Xootix Side Cart Woocommerce | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in XootiX Side Cart Woocommerce (Ajax) < 2.1 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Berocket Brands FOR Woocommerce | 18/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in BeRocket Brands for WooCommerce plugin <= 3.7.0.6 versions. | |
| Modificada | Alta (8.1) | 1.7% | — | Xootix OTP Login Woocommerce & Gravity Forms | 17/5/2023 | 17/6/2026 | The OTP Login Woocommerce & Gravity Forms plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login via phone number, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (6.5) | 0.34% | — | Woocommerce Order Status Change Notifier | 15/5/2023 | 17/6/2026 | The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without… | |
| Modificada | Media (4.8) | 0.46% | — | Themeisle Product Addons & Fields FOR Woocommerce | 15/5/2023 | 17/6/2026 | The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.6 does not sanitize and escape some of its setting fields, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite… | |
| Modificada | Media (6.1) | 0.38% | — | Woocommerce Custom Checkout Fields Editor With Drag & Drop Project Woocommerce Custom Checkout Fields Editor With Drag & Drop | 9/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Umair Saleem Woocommerce Custom Checkout Fields Editor With Drag & Drop plugin <= 0.1 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Product Specifications FOR Woocommerce Project Product Specifications FOR Woocommerce | 9/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Amin A.Rezapour Product Specifications for Woocommerce plugin <= 0.6.0 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Woocommerce Jazzcash Gateway | 9/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in JC Development Team WooCommerce JazzCash Gateway Plugin plugin <= 2.0 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Return AND Warranty Management System FOR Woocommerce Project Return AND Warranty Management System FOR Woocommerce | 8/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in chilidevs Return and Warranty Management System for WooCommerce plugin <= 1.2.3 versions. | |
| Modificada | Media (6.1) | 0.85% | 💥 Exploit | Artisanworkshop Japanized FOR Woocommerce | 8/5/2023 | 17/6/2026 | The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting | |
| Modificada | Media (5.4) | 0.50% | — | Shapedplugin Product Slider FOR Woocommerce | 8/5/2023 | 17/6/2026 | The Product Slider For WooCommerce Lite WordPress plugin through 1.1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Crítica (9.8) | 0.90% | — | Coinmarketstats Bitcoin / Altcoin Payment Gateway FOR Woocommerce | 8/5/2023 | 17/6/2026 | The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users | |
| Modificada | Media (6.1) | 0.38% | — | Rextheme Cart Lift - Abandoned Cart Recovery FOR Woocommerce AND EDD | 4/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RexTheme Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD plugin <= 3.1.5 versions. | |
| Modificada | Media (6.1) | 0.55% | — | Woocommerce Icons FOR Features | 30/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some unknown functionality of the file classes/class-icons-for-features-admin.php. The manipulation of the argument redirect_url leads to open redirect. The attack may be… | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Automattic Woocommerce PaymentsAutomattic Woopayments | 12/4/2023 | 17/6/2026 | An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated. | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Product Enquiry FOR Woocommerce | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in PI Websolution Product Enquiry for WooCommerce, WooCommerce product catalog plugin <= 2.2.12 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Product Page Shipping Calculator FOR Woocommerce | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in PI Websolution Product page shipping calculator for WooCommerce plugin <= 1.3.20 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Adtribes Product Feed PRO FOR Woocommerce | 6/4/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AdTribes.Io Product Feed PRO for WooCommerce plugin <= 12.4.4 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 5/4/2023 | 17/6/2026 | The WCFM Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying knowledge bases, modifying… | |
| Modificada | Alta (8.8) | 0.64% | — | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 5/4/2023 | 17/6/2026 | The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 due to missing capability checks on various AJAX actions. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to perform a… | |
| Modificada | Media (4.3) | 0.25% | — | Hasthemes Free Woocommerce Theme 99fy Extension | 27/3/2023 | 17/6/2026 | The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack |