Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1856 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.48% | — | Kadence Woocommerce Email DesignerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | |
| Aplazada | Crítica (9.1) | 0.49% | — | Codedropz Drag AND Drop Multiple File Upload FOR WoocommerceAI | 6/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy… | |
| Aplazada | Media (5.3) | 0.32% | — | Peprodev Woocommerce Receipt UploaderAI | 6/8/2026 | 26/8/2026 | The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they… | |
| Aplazada | Media (5.3) | 0.16% | — | Peprodev Pepro Bacs Receipt Upload FOR WoocommerceAI | 6/8/2026 | 26/8/2026 | PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated… | |
| Aplazada | Alta (7.5) | 0.41% | — | Multidots Product Attachment FOR WoocommerceAI | 2/8/2026 | 26/8/2026 | The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID. | |
| Aplazada | Alta (7.5) | 0.41% | — | AI Chatbot FOR WoocommerceAI | 2/8/2026 | 26/8/2026 | The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Wpwebelite Woocommerce Social LoginAI | 2/8/2026 | 12/8/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or… | |
| Aplazada | Media (5.3) | 0.40% | — | Woocommerce Paypal PaymentsAI | 1/8/2026 | 29/9/2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing validation on a user controlled key. This… | |
| Aplazada | Media (6.5) | 0.30% | — | Automattic Woocommerce PaymentsAI | 1/8/2026 | 26/8/2026 | The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce validation on an AJAX action that processes payment capture refunds, allowing any authenticated user, including Subscribers, to trigger refunds against captured orders. | |
| Aplazada | Media (5.3) | 0.30% | — | Direct Payments FOR WoocommerceAI | 1/8/2026 | 26/8/2026 | The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders,… | |
| Aplazada | Alta (8.8) | 0.81% | — | Subscriptions FOR WoocommerceAI | 1/8/2026 | 12/8/2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only… | |
| Aplazada | Alta (8.1) | 0.39% | — | Product Feed Manager FOR WoocommerceAI | 31/7/2026 | 26/8/2026 | The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks. | |
| Aplazada | Alta (7.2) | 0.58% | — | Subscriptions FOR WoocommerceAI | 30/7/2026 | 30/7/2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible… | |
| Aplazada | Media (5.9) | 0.29% | — | Weblizar Points AND Rewards FOR WoocommerceAIWeblizar Wallet System FOR WoocommerceAI | 30/7/2026 | 30/7/2026 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily… | |
| Aplazada | Media (4.3) | 0.40% | — | Eventbooking Event Booking Manager FOR WoocommerceAI | 29/7/2026 | 30/7/2026 | The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Alta (8.8) | 0.52% | — | Wpexperts Wholesale FOR WoocommerceAI | 29/7/2026 | 30/7/2026 | The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with… | |
| Aplazada | Media (4.4) | 0.52% | — | SMS Alert SMS OTP FOR Woocommerce Order Notifications Abandoned Cart RecoveryAI | 28/7/2026 | 28/7/2026 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack… | |
| Aplazada | Media (6.5) | 0.37% | — | Yookassa Yukassa FOR WoocommerceAI | 27/7/2026 | 27/7/2026 | Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Stripe FOR WoocommerceAI | 27/7/2026 | 27/7/2026 | Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions. | |
| Aplazada | Crítica (9) | 0.67% | — | Facturone Para Woocommerce CON VerifactuAI | 27/7/2026 | 27/7/2026 | The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible… | |
| Aplazada | Alta (8.1) | 0.41% | 💥 PoC | Custom Fields Account Registration FOR WoocommerceAI | 27/7/2026 | 27/7/2026 | The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator… | |
| Aplazada | Media (6.5) | 0.79% | — | Themehigh Checkout Field Editor FOR WoocommerceAI | 25/7/2026 | 27/7/2026 | The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary… | |
| Aplazada | Media (6.4) | 0.33% | — | Berocket Brands FOR WoocommerceAI | 24/7/2026 | 24/7/2026 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Alta (7.6) | 0.38% | — | Persian Woocommerce SMSAI | 23/7/2026 | 23/7/2026 | Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Shiptastic FOR WoocommerceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions. |