Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1856 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.48%—Kadence Woocommerce Email DesignerAI6/8/202612/8/2026
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
AplazadaCrítica (9.1)0.49%—Codedropz Drag AND Drop Multiple File Upload FOR WoocommerceAI6/8/202626/8/2026
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy…
AplazadaMedia (5.3)0.32%—Peprodev Woocommerce Receipt UploaderAI6/8/202626/8/2026
The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they…
AplazadaMedia (5.3)0.16%—Peprodev Pepro Bacs Receipt Upload FOR WoocommerceAI6/8/202626/8/2026
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated…
AplazadaAlta (7.5)0.41%—Multidots Product Attachment FOR WoocommerceAI2/8/202626/8/2026
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.
AplazadaAlta (7.5)0.41%—AI Chatbot FOR WoocommerceAI2/8/202626/8/2026
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to…
AplazadaCrítica (9.8)0.70%—Wpwebelite Woocommerce Social LoginAI2/8/202612/8/2026
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or…
AplazadaMedia (5.3)0.40%—Woocommerce Paypal PaymentsAI1/8/202629/9/2026
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing validation on a user controlled key. This…
AplazadaMedia (6.5)0.30%—Automattic Woocommerce PaymentsAI1/8/202626/8/2026
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders.
AplazadaMedia (5.3)0.30%—Direct Payments FOR WoocommerceAI1/8/202626/8/2026
The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders,…
AplazadaAlta (8.8)0.81%—Subscriptions FOR WoocommerceAI1/8/202612/8/2026
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only…
AplazadaAlta (8.1)0.39%—Product Feed Manager FOR WoocommerceAI31/7/202626/8/2026
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.
AplazadaAlta (7.2)0.58%—Subscriptions FOR WoocommerceAI30/7/202630/7/2026
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible…
AplazadaMedia (5.9)0.29%—Weblizar Points AND Rewards FOR WoocommerceAIWeblizar Wallet System FOR WoocommerceAI30/7/202630/7/2026
The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily…
AplazadaMedia (4.3)0.40%—Eventbooking Event Booking Manager FOR WoocommerceAI29/7/202630/7/2026
The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
AplazadaAlta (8.8)0.52%—Wpexperts Wholesale FOR WoocommerceAI29/7/202630/7/2026
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with…
AplazadaMedia (4.4)0.52%—SMS Alert SMS OTP FOR Woocommerce Order Notifications Abandoned Cart RecoveryAI28/7/202628/7/2026
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack…
AplazadaMedia (6.5)0.37%—Yookassa Yukassa FOR WoocommerceAI27/7/202627/7/2026
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
AplazadaAlta (7.5)0.35%—Stripe FOR WoocommerceAI27/7/202627/7/2026
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
AplazadaCrítica (9)0.67%—Facturone Para Woocommerce CON VerifactuAI27/7/202627/7/2026
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible…
AplazadaAlta (8.1)0.41%💥 PoCCustom Fields Account Registration FOR WoocommerceAI27/7/202627/7/2026
The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator…
AplazadaMedia (6.5)0.79%—Themehigh Checkout Field Editor FOR WoocommerceAI25/7/202627/7/2026
The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary…
AplazadaMedia (6.4)0.33%—Berocket Brands FOR WoocommerceAI24/7/202624/7/2026
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaAlta (7.6)0.38%—Persian Woocommerce SMSAI23/7/202623/7/2026
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
AplazadaMedia (5.3)0.31%—Shiptastic FOR WoocommerceAI23/7/202623/7/2026
Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.