Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.27% | — | Themekraft Buddypress Woocommerce MY Account Integration | 1/3/2025 | 17/6/2026 | The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wc4bp_delete_page() function in all versions up to, and including, 3.4.25. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (4.3) | 0.27% | — | Themekraft Buddypress Woocommerce MY Account Integration | 1/3/2025 | 17/6/2026 | The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wc4bp_delete_page() function in all versions up to, and including, 3.4.24. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.36% | — | Themekraft Buddypress Woocommerce MY Account Integration. Create Woocommerce Member Pages | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.19. | |
| Modificada | Alta (8.8) | 0.51% | — | Themekraft Buddypress Woocommerce MY Account Integration | 18/4/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20. | |
| Aplazada | Alta (8.8) | 0.81% | — | Themekraft Buddypress Woocommerce MY Account IntegrationAI | 23/3/2024 | 17/6/2026 | The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.20 via deserialization of untrusted input in the get_simple_request function. This makes it possible for authenticated attackers,… |