Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 306 respecto a la semana anterior
Críticas / altas1347▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.29% | — | Eprolo DropshippingAI | 20/8/2026 | 24/8/2026 | Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions. | |
| Aplazada | Media (4.8) | 0.26% | — | ALD Dropshipping AND FulfillmentAI | 2/7/2026 | 2/7/2026 | Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Syncee Premium Dropshipping AND WholesaleAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Access Control in Syncee Premium Dropshipping & Wholesale <= 1.0.27 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Opmc Woocommerce DropshippingAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions. | |
| Aplazada | Media (4.3) | 0.22% | — | Eprolo DropshippingAI | 5/12/2025 | 25/9/2026 | The EPROLO Dropshipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_eprolo_delete_tracking and wp_ajax_eprolo_save_tracking_data AJAX endpoints in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.29% | — | Bigbuy Dropshipping ConnectorAI | 21/11/2025 | 17/6/2026 | The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.5 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated… | |
| Modificada | Media (5.3) | 0.62% | — | Bigbuy Dropshipping Connector FOR Woocommerce | 18/2/2025 | 17/6/2026 | The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.0. This is due the /vendor/cocur/slugify/bin/generate-default.php file being directly accessible and triggering an error. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.53% | — | Villatheme ALD Dropshipping AND Fulfillment FOR Aliexpress AND WoocommerceAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in VillaTheme(villatheme.com) ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce: from n/a through 1.0.21. | |
| Aplazada | Media (6.5) | 0.53% | — | Sharkdropship Woo-aliexpress-dropshippingAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Marc dooder Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy woo-aliexpress-dropshipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a through <=… | |
| Aplazada | Media (6.5) | 0.26% | — | Dropshipping Guru Ali2woo LiteAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Dropshipping Guru Ali2Woo Lite Exploiting Incorrectly Configured Access Control Security Levels, Stored XSS.This issue affects Ali2Woo Lite: from n/a through 3.3.5. | |
| Modificada | Media (6.1) | 0.27% | — | Ali2woo Aliexpress Dropshipping With Alinext | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ali2Woo Team Ali2Woo Lite allows Reflected XSS.This issue affects Ali2Woo Lite: from n/a through 3.3.5. | |
| Analizada | Alta (8.8) | 0.21% | — | Ali2woo Aliexpress Dropshipping With Alinext | 21/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ali2Woo Ali2Woo Lite.This issue affects Ali2Woo Lite: from n/a through 3.3.5. | |
| Modificada | Media (6.3) | 0.33% | — | Ali2woo Aliexpress Dropshipping With Alinext | 19/6/2024 | 17/6/2026 | The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ImportAjaxController.php file in all versions up to, and including, 3.3.6. This makes it possible for authenticated attackers, with subscriber-level… | |
| Modificada | Alta (8.8) | 0.91% | — | Ali2woo Aliexpress Dropshipping With Alinext | 19/6/2024 | 17/6/2026 | The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_save_image function in all versions up to, and including, 3.3.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (5.3) | 0.31% | — | Opmc Woocommerce Dropshipping | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in OPMC WooCommerce Dropshipping.This issue affects WooCommerce Dropshipping: from n/a through 5.0.4. | |
| Aplazada | Alta (7.5) | 0.76% | — | Sharkdropship DropshippingAI | 14/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Woo product importer Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a through 2.1.1. | |
| Aplazada | Media (4.3) | 0.37% | — | Eprolo DropshippingAI | 8/5/2024 | 17/6/2026 | Missing Authorization vulnerability in EPROLO EPROLO Dropshipping.This issue affects EPROLO Dropshipping: from n/a through 1.7.1. | |
| Aplazada | Media (5.3) | 0.40% | — | Sharkdropship FOR Aliexpress Dropshipping AND AffiliateAI | 2/4/2024 | 17/6/2026 | The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wads_removeProductFromShop() function in all versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to delete… | |
| Modificada | Alta (8.8) | 0.64% | — | Amadercode Dropshipping & Affiliation With Amazon | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in AmaderCode Lab Dropshipping & Affiliation with Amazon.This issue affects Dropshipping & Affiliation with Amazon: from n/a through 2.1.2. | |
| Modificada | Alta (7.5) | 0.89% | — | Syncee - Global Dropshipping | 5/12/2022 | 17/6/2026 | The Syncee WordPress plugin before 1.0.10 leaks the administrator token that can be used to take over the administrator's account. | |
| Modificada | Crítica (9.8) | 3.9% | — | Opmc Woocommerce Dropshipping | 7/11/2022 | 17/6/2026 | The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection | |
| Modificada | Alta (7.5) | 0.79% | — | Villatheme Dropshipping AND Fulfillment FOR Aliexpress AND Woocommerce | 14/10/2022 | 17/6/2026 | Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 on WordPress. |