Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.34% | — | Wpeasypay WP Easy PAYAI | 18/9/2026 | 19/9/2026 | The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.35% | — | Wpeasypay WP EasypayAI | 3/9/2026 | 3/9/2026 | Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | Wpeasypay WP EasypayAI | 23/7/2026 | 23/7/2026 | Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions. | |
| Aplazada | Media (4.3) | 0.37% | — | Wpeasypay WP Easy PAYAI | 11/7/2026 | 13/7/2026 | The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.18% | — | Wpeasypay WP EasypayAI | 18/6/2026 | 1/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.5.0. | |
| Modificada | Media (6.5) | 0.40% | — | Wpeasypay WP Easypay | 24/7/2024 | 17/6/2026 | The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() function in all versions up to, and including, 4.2.3. This makes it possible for unauthenticated attackers to disconnect square. | |
| Modificada | Media (6.1) | 0.46% | — | Wpeasypay WP Easypay | 16/8/2023 | 17/6/2026 | The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin | |
| Modificada | Crítica (9.8) | 0.50% | — | Nesote Inout Blockchain Easypayments | 15/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Nesote Inout Blockchain EasyPayments 1.0. Affected is an unknown function of the file /index.php/payment/getcoinaddress of the component POST Parameter Handler. The manipulation of the argument coinid leads to sql injection. It is possible to launch the… | |
| Modificada | Media (4.3) | 0.40% | — | Wpeasypay WP Easypay | 12/7/2023 | 17/6/2026 | The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the wpep_download_transaction_in_excel() function. This makes it possible for unauthenticated attackers to trigger a… | |
| Modificada | Alta (8.8) | 0.30% | — | Wpeasypay WP Easypay | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Easy Pay WP EasyPay – Square for WordPress plugin <= 4.1 versions. | |
| Modificada | Media (5.4) | 0.53% | — | Sage Easypay | 18/10/2020 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in Sage EasyPay 10.7.5.10 allow authenticated attackers to inject arbitrary web script or HTML via multiple parameters through Unicode Transformations (Best-fit Mapping), as demonstrated by the full-width variants of the less-than sign (%EF%BC%9C) and… |