Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.22% | — | Wpeasycart WP EasycartAI | 23/9/2026 | 23/9/2026 | Contributor SQL Injection in WP EasyCart <= 5.9.4 versions. | |
| Aplazada | Alta (7.2) | 0.43% | — | Wpeasycart WP EasycartAI | 9/9/2026 | 9/9/2026 | The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX handler iterating over every $_POST key and passing it directly into update_option() without any allowlist, while gating the handler only on… | |
| Aplazada | Alta (8.5) | 0.36% | — | Wpeasycart WP EasycartAI | 2/7/2026 | 2/7/2026 | Contributor SQL Injection in WP EasyCart <= 5.9.0 versions. | |
| Aplazada | Media (6.4) | 0.43% | — | Easycart Easy CartAI | 2/6/2026 | 22/7/2026 | The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1.8. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the ectp_add_to_cart() function uses… | |
| Aplazada | Alta (8.5) | 0.36% | — | Levelfourdevelopment WP EasycartAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Blind SQL Injection.This issue affects WP EasyCart: from n/a through <= 5.8.13. | |
| Aplazada | Media (5.1) | 0.34% | — | Easycart Easy Cart Shopping CartAI | 1/2/2026 | 17/6/2026 | Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword parameter. Remote attackers can inject malicious script code through the search input to compromise user sessions and manipulate application content. | |
| Aplazada | Media (5.3) | 0.29% | — | Levelfourdevelopment WP EasycartAI | 9/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Retrieve Embedded Sensitive Data.This issue affects WP EasyCart: from n/a through <= 5.8.11. | |
| Aplazada | Media (5.3) | 0.38% | — | Wpeasycart WP EasycartAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19. | |
| Aplazada | Media (5.4) | 0.21% | — | Wpeasycart WP EasycartAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19. | |
| Modificada | Alta (7.2) | 0.70% | — | Wpeasycart WP Easycart | 12/7/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in versions up to, and including, 5.4.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Modificada | Media (4.3) | 0.24% | — | Wpeasycart WP Easycart | 9/6/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_duplicate_product function. This makes it possible for unauthenticated attackers to duplicate products via a forged request… | |
| Modificada | Media (4.3) | 0.24% | — | Wpeasycart WP Easycart | 9/6/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_activate_product function. This makes it possible for unauthenticated attackers to bulk activate products via a forged… | |
| Modificada | Media (4.3) | 0.24% | — | Wpeasycart WP Easycart | 9/6/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_deactivate_product function. This makes it possible for unauthenticated attackers to bulk deactivate products via a forged… | |
| Modificada | Media (4.3) | 0.24% | — | Wpeasycart WP Easycart | 9/6/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_deactivate_product function. This makes it possible for unauthenticated attackers to deactivate products via a forged request… | |
| Modificada | Media (4.3) | 0.23% | — | Wpeasycart WP Easycart | 9/6/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_delete_product function. This makes it possible for unauthenticated attackers to bulk delete products via a forged request… | |
| Modificada | Media (4.3) | 0.24% | — | Wpeasycart WP Easycart | 9/6/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_delete_product function. This makes it possible for unauthenticated attackers to delete products via a forged request granted… | |
| Modificada | Alta (7.2) | 1.1% | — | Wpeasycart WP Easycart | 3/4/2023 | 17/6/2026 | The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks. | |
| Modificada | Alta (8.8) | 0.64% | — | Wpeasycart Shopping Cart & Ecommerce Store | 19/8/2021 | 17/6/2026 | The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.1.0. | |
| Modificada | Alta (8.8) | 19% | — | Wpeasycart WP Easycart | 6/10/2017 | 17/6/2026 | The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain administrator privileges and execute arbitrary code via the option_name and option_value parameters. | |
| Modificada | Media (6.5) | 51% | 💥 Exploit | Wpeasycart WP Easycart | 15/1/2015 | 17/6/2026 | Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin before 3.0.9 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the… | |
| Modificada | Media (5) | 4.5% | 💥 Exploit | Levelfourdevelopment Wp-easycart | 11/7/2014 | 17/6/2026 | The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls the phpinfo function. | |
| Modificada | Alta (7.5) | 2.0% | — | Easycart | 1/2/2000 | 16/6/2026 | The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. |