Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1856 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.9. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpdesk Flexible Refund AND Return Order FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Refund and Return Order for WooCommerce flexible-refund-and-return-order-for-woocommerce allows Stored XSS.This issue affects Flexible Refund and Return Order for WooCommerce: from n/a through <=… | |
| Aplazada | Media (6.5) | 0.33% | — | Wpswings Event Tickets Manager FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5. | |
| Aplazada | Alta (7.1) | 0.25% | — | Flintop Free-gifts-for-woocommerceAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flintop Free Gifts for WooCommerce free-gifts-for-woocommerce allows Stored XSS.This issue affects Free Gifts for WooCommerce: from n/a through <= 13.1.0. | |
| Aplazada | Media (6.5) | 0.33% | — | Edgarrojas Extra Product Options Builder FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extra Product Options Builder for WooCommerce: from n/a through <= 1.2.167. | |
| Aplazada | Alta (7.2) | 0.56% | — | Corvuspay Woocommerce Payment GatewayAI | 11/7/2026 | 13/7/2026 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (4.3) | 0.49% | — | Wallet FOR WoocommerceAI | 11/7/2026 | 13/7/2026 | The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Aplazada | Media (4.3) | 0.39% | — | Wpdesk PDF Invoices Packing Slips FOR WoocommerceAI | 11/7/2026 | 13/7/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.34% | — | DHL Ecommerce Benelux FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing nonce verification on the create_label() and delete_label() functions in versions up to, and including, 2.2.3. These functions are wired to the… | |
| Aplazada | Media (5.3) | 0.47% | — | Corvuspay Woocommerce Payment GatewayAI | 9/7/2026 | 9/7/2026 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to cancel any… | |
| Aplazada | Media (6.4) | 0.42% | — | Cusrev Customer Reviews FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all versions up to, and including, 5.113.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (4.3) | 0.34% | — | Profilegrid Memberships AND User Profiles FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid()… | |
| Aplazada | Media (5.3) | 0.47% | — | Bulk Order Update FOR WoocommerceAI | 8/7/2026 | 8/7/2026 | The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. This is due to the bouw_fetch_csv_data() AJAX handler being registered on the wp_ajax_nopriv_ hook with no capability or nonce check, and passing the attacker-supplied csv_url POST… | |
| Aplazada | Alta (7.5) | 0.68% | — | AR FOR WoocommerceAI | 3/7/2026 | 6/7/2026 | The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The three… | |
| Aplazada | Media (5.3) | 0.33% | — | KIT FOR WoocommerceAI | 2/7/2026 | 2/7/2026 | Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Customize MY Account FOR WoocommerceAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mildainc MC Woocommerce WishlistAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions. | |
| Aplazada | Media (6.5) | 0.44% | — | Addify TAX Exempt FOR WoocommerceAI | 2/7/2026 | 28/7/2026 | Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5. | |
| Aplazada | Alta (7.5) | 0.35% | — | Nowpayments FOR WoocommerceAI | 2/7/2026 | 2/7/2026 | Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions. | |
| Aplazada | Media (4.4) | 0.34% | 💥 PoC | Product Video Gallery FOR WoocommerceAI | 2/7/2026 | 2/7/2026 | The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_thumbnail Parameter in all versions up to, and including, 1.5.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop… | |
| Aplazada | Media (4.3) | 0.39% | — | Envothemes Templates Widgets FOR Elementor AND WoocommerceAI | 2/7/2026 | 2/7/2026 | The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's template rendering in versions up to, and including, 1.4.26. The render() method of the Tabs widget passes a… | |
| Aplazada | Alta (7.5) | 0.46% | — | Product Configurator FOR WoocommerceAI | 1/7/2026 | 1/7/2026 | The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status check before returning WooCommerce product data through a public AJAX action, allowing unauthenticated users to retrieve the data (title, price, weight, stock status, and configurator option… | |
| Aplazada | Alta (7.2) | 0.43% | — | Algoritmika Custom Payment Gateways FOR WoocommerceAI | 1/7/2026 | 1/7/2026 | The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alg_wc_cpg_input_fields' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.5) | 0.33% | — | Colissimo Officiel Methodes DE Livraison Pour WoocommerceAI | 29/6/2026 | 1/7/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Artisanworkshop Japanized FOR WoocommerceAI | 29/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions. |