Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.37%—FOX Currency Switcher ProfessionalAI28/5/202617/6/2026
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the attacker-controlled…
AplazadaAlta (8.1)0.50%—FOX Currency Switcher ProfessionalAI15/5/202617/6/2026
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above,…
AplazadaAlta (7.3)0.46%—Thefox FOX Currency Switcher ProfessionalAI9/11/202417/6/2026
The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes…
AnalizadaAlta (7.3)0.74%—Pluginus FOX - Currency Switcher Professional FOR Woocommerce14/9/202417/6/2026
The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode in the…
AplazadaMedia (6.5)1.0%—Pluginus FOX - Currency Switcher Professional FOR WoocommerceAI2/5/202417/6/2026
The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 1.4.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what other plugins are installed…
ModificadaAlta (8.8)0.24%—Pluginus FOX - Currency Switcher Professional FOR Woocommerce29/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7.
ModificadaAlta (8.8)1.3%—Pluginus FOX - Currency Switcher Professional FOR Woocommerce16/1/202417/6/2026
The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.
ModificadaMedia (5.4)0.41%—Pluginus FOX - Currency Switcher Professional FOR Woocommerce11/1/202417/6/2026
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
ModificadaAlta (8.8)0.25%—Pluginus FOX - Currency Switcher Professional FOR Woocommerce17/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 FOX – Currency Switcher Professional for WooCommerce.This issue affects FOX – Currency Switcher Professional for WooCommerce: from n/a through 1.4.1.4.
ModificadaMedia (5.4)0.36%—Pluginus Wordpress Currency Switcher Professional9/6/202317/6/2026
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcs_current_currency shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
ModificadaMedia (4.3)0.41%—Pluginus Wordpress Currency Switcher Professional9/6/202317/6/2026
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to…
ModificadaMedia (4.3)0.43%—Pluginus Wordpress Currency Switcher Professional9/6/202317/6/2026
The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above,…
ModificadaMedia (5.4)0.50%—Pluginus FOX - Currency Switcher Professional FOR Woocommerce16/1/202317/6/2026
The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.