Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2833▲ 195 respecto a la semana anterior
Críticas / altas1316▼ 117 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1872 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.41%—Levantoan Woocommerce Vietnam Checkout27/3/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Le Van Toan Woocommerce Vietnam Checkout plugin <= 2.0.4 versions.
ModificadaMedia (4.8)0.39%—Thisfunctional CTT Expresso Para Woocommerce23/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in this.Functional CTT Expresso para WooCommerce plugin <= 3.2.11 versions.
ModificadaMedia (4.8)0.37%—Mage-people Event Manager AND Tickets Selling FOR Woocommerce23/3/202317/6/2026
Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions.
ModificadaMedia (5.4)0.89%💥 ExploitTechnocrackers Bulk Price Update FOR Woocommerce22/3/202317/6/2026
The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.
ModificadaAlta (8.8)1.2%—Woocommerce Multiple Customer Addresses & Shipping Project Woocommerce Multiple Customer Addresses & Shipping20/3/202317/6/2026
The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete…
ModificadaAlta (8.8)0.26%—Piwebsolution CSS JS Manager, Async Javascript, Defer Render Blocking CSS Supports Woocommerce14/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions.
ModificadaMedia (5.4)0.47%—Themelocation Widgets FOR Woocommerce Products ON Elementor13/3/202317/6/2026
The Widgets for WooCommerce Products on Elementor WordPress plugin before 1.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting…
ModificadaMedia (5.4)0.47%—Product Gtin (ean, Upc, Isbn) FOR Woocommerce Project Product Gtin (ean, Upc, Isbn) FOR Woocommerce6/3/202317/6/2026
The Product GTIN (EAN, UPC, ISBN) for WooCommerce WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting…
ModificadaCrítica (9.8)4.4%💥 ExploitNajeebmedia Woocommerce Checkout Field Manager6/3/202317/6/2026
The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server
ModificadaMedia (4.3)0.23%—Wpovernight Woocommerce PDF Invoices& Packing Slips1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.
ModificadaMedia (4.3)0.22%—Villatheme Cart ALL IN ONE FOR Woocommerce1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Cart All In One For WooCommerce plugin <= 1.1.10 leading to cart modification.
ModificadaMedia (5.4)0.21%—Wptrio Conditional Shipping FOR Woocommerce1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 leading to activation/deactivation of plugin rulesets.
ModificadaMedia (5.4)0.23%—Hasthemes Woolentor - Woocommerce Elementor Addons + Builder1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change.
ModificadaAlta (8.8)0.29%—Mercadopago Mercado Pago Payments FOR Woocommerce1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mercado Pago Mercado Pago payments for WooCommerce plugin <= 6.3.1.
ModificadaMedia (4.3)0.23%—Checkoutplugins Stripe Payments FOR Woocommerce28/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce plugin <= 1.4.10 leads to settings change.
ModificadaMedia (6.1)1.2%💥 ExploitArtisanworkshop Japanized FOR Woocommerce21/2/202317/6/2026
The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
ModificadaMedia (5.4)0.47%—Essentialplugin Product Slider AND Carousel With Category With Woocommerce21/2/202317/6/2026
The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
ModificadaMedia (5.4)0.48%—Pickplugins Product Slider FOR Woocommerce13/2/202317/6/2026
The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting…
ModificadaAlta (8.8)1.1%—Cusrev Customer Reviews FOR Woocommerce13/2/202317/6/2026
The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also…
ModificadaMedia (5.4)0.64%—Judge Product Reviews FOR Woocommerce13/2/202317/6/2026
The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.48%—Mage-people Event Manager AND Tickets Selling FOR Woocommerce6/2/202317/6/2026
The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.57%—Wpfactory EAN FOR Woocommerce6/2/202317/6/2026
The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (7.2)1.3%—Pluginus Husky - Products Filter Professional FOR Woocommerce6/2/202317/6/2026
The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
ModificadaMedia (6.1)0.43%—Afterpay Gateway FOR Woocommerce6/2/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Afterpay Gateway for WooCommerce <= 3.5.0 versions.
ModificadaAlta (8.8)0.26%—Wptrio Conditional Shipping FOR Woocommerce2/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 versions.