Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
3217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.3) | 0.18% | — | Mailchimp FOR WoocommerceAI | 3/10/2026 | 3/10/2026 | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart. | |
| Recibida | Media (4.3) | 0.16% | — | Helpdesk Support Ticket System FOR WoocommerceAI | 3/10/2026 | 3/10/2026 | The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level… | |
| Recibida | Alta (8.1) | 0.34% | — | Photo Reviews FOR WoocommerceAI | 3/10/2026 | 3/10/2026 | The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta… | |
| Aplazada | Media (5.3) | 0.20% | — | Softtr Informatics E-commerce PackAI | 2/10/2026 | 2/10/2026 | Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting. This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (7.2) | 0.24% | — | Cusrev Customer Reviews FOR WoocommerceAI | 2/10/2026 | 2/10/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (6.5) | 0.31% | — | DC Woocommerce Multi VendorAI | 2/10/2026 | 3/10/2026 | The Dc Woocommerce Multi Vendor plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter of the /multivendorx/v1/compliance/report-abuse REST endpoint in versions up to and including 5.0.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation… | |
| Aplazada | Media (5.3) | 0.26% | — | Webtoffee Gift Cards FOR WoocommerceAI | 2/10/2026 | 2/10/2026 | The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations… | |
| Aplazada | Alta (7.2) | 0.37% | — | Hide Shipping Method FOR WoocommerceAI | 1/10/2026 | 1/10/2026 | Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. | |
| Aplazada | Alta (7.5) | 0.30% | — | Photo Reviews FOR WoocommerceAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions. | |
| Aplazada | Alta (7.2) | 0.28% | — | PDF Invoices Packing Slips FOR WoocommerceAI | 1/10/2026 | 1/10/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.22% | — | WP Hosting AS PAY With Vipps FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.4. | |
| Aplazada | Media (5.4) | 0.10% | — | Razorpay Payment Links FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions. | |
| Aplazada | Media (6.5) | 0.13% | — | Yith Woocommerce TAB ManagerAI | 30/9/2026 | 30/9/2026 | Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions. | |
| Aplazada | Alta (7.6) | 0.28% | — | Quanticedgesolutions Category Discount WoocommerceAI | 30/9/2026 | 30/9/2026 | Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Cusrev Customer Reviews FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. | |
| Aplazada | Alta (8.2) | 0.36% | — | MakecommerceAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Trusted Shops Easy Integration FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | WOO Commerce Product Table LiteAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Yithemes Yith Woocommerce Ajax SearchAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Implecode Ecommerce Product CatalogAI | 30/9/2026 | 30/9/2026 | Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. | |
| Aplazada | Alta (7.2) | 0.40% | — | Kadencewp Kadence Woocommerce Email DesignerAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Wpfactory Cost OF Goods FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Minimum AND Maximum Quantity FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Music Player FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. | |
| Aplazada | Alta (8.8) | 0.28% | — | Verge3d Publishing AND E CommerceAI | 30/9/2026 | 30/9/2026 | The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the… |