Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.74% | — | Pluginus FOX - Currency Switcher Professional FOR Woocommerce | 14/9/2024 | 17/6/2026 | The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode in the… | |
| Aplazada | Media (6.5) | 1.0% | — | Pluginus FOX - Currency Switcher Professional FOR WoocommerceAI | 2/5/2024 | 17/6/2026 | The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 1.4.1.8. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on what other plugins are installed… | |
| Modificada | Alta (8.8) | 0.24% | — | Pluginus FOX - Currency Switcher Professional FOR Woocommerce | 29/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7. | |
| Modificada | Alta (8.8) | 1.3% | — | Pluginus FOX - Currency Switcher Professional FOR Woocommerce | 16/1/2024 | 17/6/2026 | The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode. | |
| Modificada | Media (5.4) | 0.41% | — | Pluginus FOX - Currency Switcher Professional FOR Woocommerce | 11/1/2024 | 17/6/2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via currency options in all versions up to, and including, 1.4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.25% | — | Pluginus FOX - Currency Switcher Professional FOR Woocommerce | 17/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 FOX – Currency Switcher Professional for WooCommerce.This issue affects FOX – Currency Switcher Professional for WooCommerce: from n/a through 1.4.1.4. | |
| Modificada | Media (5.4) | 0.50% | — | Pluginus FOX - Currency Switcher Professional FOR Woocommerce | 16/1/2023 | 17/6/2026 | The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. |