Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 195 respecto a la semana anterior
Críticas / altas1316▼ 117 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.41% | — | Levantoan Woocommerce Vietnam Checkout | 27/3/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Le Van Toan Woocommerce Vietnam Checkout plugin <= 2.0.4 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Thisfunctional CTT Expresso Para Woocommerce | 23/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in this.Functional CTT Expresso para WooCommerce plugin <= 3.2.11 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 23/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions. | |
| Modificada | Media (5.4) | 0.89% | 💥 Exploit | Technocrackers Bulk Price Update FOR Woocommerce | 22/3/2023 | 17/6/2026 | The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user. | |
| Modificada | Alta (8.8) | 1.2% | — | Woocommerce Multiple Customer Addresses & Shipping Project Woocommerce Multiple Customer Addresses & Shipping | 20/3/2023 | 17/6/2026 | The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete… | |
| Modificada | Alta (8.8) | 0.26% | — | Piwebsolution CSS JS Manager, Async Javascript, Defer Render Blocking CSS Supports Woocommerce | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Themelocation Widgets FOR Woocommerce Products ON Elementor | 13/3/2023 | 17/6/2026 | The Widgets for WooCommerce Products on Elementor WordPress plugin before 1.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting… | |
| Modificada | Media (5.4) | 0.47% | — | Product Gtin (ean, Upc, Isbn) FOR Woocommerce Project Product Gtin (ean, Upc, Isbn) FOR Woocommerce | 6/3/2023 | 17/6/2026 | The Product GTIN (EAN, UPC, ISBN) for WooCommerce WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting… | |
| Modificada | Crítica (9.8) | 4.4% | 💥 Exploit | Najeebmedia Woocommerce Checkout Field Manager | 6/3/2023 | 17/6/2026 | The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server | |
| Modificada | Media (4.3) | 0.23% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss. | |
| Modificada | Media (4.3) | 0.22% | — | Villatheme Cart ALL IN ONE FOR Woocommerce | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Cart All In One For WooCommerce plugin <= 1.1.10 leading to cart modification. | |
| Modificada | Media (5.4) | 0.21% | — | Wptrio Conditional Shipping FOR Woocommerce | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 leading to activation/deactivation of plugin rulesets. | |
| Modificada | Media (5.4) | 0.23% | — | Hasthemes Woolentor - Woocommerce Elementor Addons + Builder | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change. | |
| Modificada | Alta (8.8) | 0.29% | — | Mercadopago Mercado Pago Payments FOR Woocommerce | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mercado Pago Mercado Pago payments for WooCommerce plugin <= 6.3.1. | |
| Modificada | Media (4.3) | 0.23% | — | Checkoutplugins Stripe Payments FOR Woocommerce | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce plugin <= 1.4.10 leads to settings change. | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Artisanworkshop Japanized FOR Woocommerce | 21/2/2023 | 17/6/2026 | The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Media (5.4) | 0.47% | — | Essentialplugin Product Slider AND Carousel With Category With Woocommerce | 21/2/2023 | 17/6/2026 | The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Modificada | Media (5.4) | 0.48% | — | Pickplugins Product Slider FOR Woocommerce | 13/2/2023 | 17/6/2026 | The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting… | |
| Modificada | Alta (8.8) | 1.1% | — | Cusrev Customer Reviews FOR Woocommerce | 13/2/2023 | 17/6/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also… | |
| Modificada | Media (5.4) | 0.64% | — | Judge Product Reviews FOR Woocommerce | 13/2/2023 | 17/6/2026 | The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.48% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 6/2/2023 | 17/6/2026 | The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.57% | — | Wpfactory EAN FOR Woocommerce | 6/2/2023 | 17/6/2026 | The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (7.2) | 1.3% | — | Pluginus Husky - Products Filter Professional FOR Woocommerce | 6/2/2023 | 17/6/2026 | The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present. | |
| Modificada | Media (6.1) | 0.43% | — | Afterpay Gateway FOR Woocommerce | 6/2/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Afterpay Gateway for WooCommerce <= 3.5.0 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Wptrio Conditional Shipping FOR Woocommerce | 2/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 versions. |