Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
477 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | — | — | Airwallex Online Payments GatewayAI | 8/10/2026 | 8/10/2026 | The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying. | |
| Aplazada | Media (4.3) | 0.15% | — | Yaad Sarig Payment Gateway FOR WCAI | 7/10/2026 | 7/10/2026 | The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting user owns the target order in several of its order payment-processing actions, allowing any authenticated user, including subscribers, to act on and alter orders belonging to other customers. | |
| Aplazada | Alta (7.1) | 0.15% | — | Tomlister Payflex Payment GatewayAI | 6/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1. | |
| Aplazada | Media (6.5) | 0.16% | — | Elegro Crypto PaymentAI | 6/10/2026 | 6/10/2026 | The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been… | |
| Aplazada | Media (5.3) | 0.18% | — | Deema Payment GatewayAI | 6/10/2026 | 6/10/2026 | The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status or amount, allowing unauthenticated users to have orders marked as paid without any payment being taken. | |
| Aplazada | Media (5.3) | 0.18% | — | Deema Payment GatewayAI | 6/10/2026 | 6/10/2026 | The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing unauthenticated attackers to mark an unpaid order as paid, or to cancel or refund an existing order. | |
| Aplazada | Media (5.3) | 0.18% | — | UPI QR Code Payment GatewayAI | 5/10/2026 | 6/10/2026 | The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment. | |
| Aplazada | Media (5.3) | 0.18% | — | Paytm Payment GatewayAI | 2/10/2026 | 2/10/2026 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders,… | |
| Aplazada | Alta (7.5) | 0.26% | — | Payments FOR HubtelAI | 1/10/2026 | 1/10/2026 | The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials. | |
| Aplazada | Media (5.3) | 0.18% | — | Payments FOR HubtelAI | 1/10/2026 | 1/10/2026 | The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing unauthenticated attackers to mark arbitrary orders as paid without payment. | |
| Aplazada | Media (5.3) | 0.19% | — | Payments FOR HubtelAI | 1/10/2026 | 1/10/2026 | The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback request, allowing unauthenticated attackers to obtain the order key of an arbitrary order and view its contents. | |
| Aplazada | Alta (7.5) | 0.18% | — | Paytm Payment GatewayAI | 1/10/2026 | 1/10/2026 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection… | |
| Aplazada | Alta (7.5) | 0.22% | — | Paytm Payment GatewayAI | 1/10/2026 | 1/10/2026 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts… | |
| Aplazada | Media (5.4) | 0.10% | — | Razorpay Payment Links FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions. | |
| Aplazada | Media (6.5) | 0.25% | — | Conekta Payment GatewayAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions. | |
| Aplazada | Alta (7.1) | 0.19% | — | Razorpay Payment ButtonAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions. | |
| Aplazada | Media (6.5) | 0.19% | — | Payplus Payment GatewayAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions. | |
| Aplazada | Media (5.3) | 0.18% | — | Sumit Payment GatewayAI | 23/9/2026 | 24/9/2026 | The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment. | |
| Aplazada | Media (6.5) | 0.20% | — | Payment Plugins FOR Paypal WoocommerceAI | 23/9/2026 | 23/9/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, allowing unauthenticated attackers to have another buyer's approved but uncaptured… | |
| Aplazada | Media (5.3) | 0.22% | — | Better PaymentAI | 23/9/2026 | 23/9/2026 | The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbitrary reduced amount for a fixed-price item. | |
| Aplazada | Media (5.3) | 0.16% | — | Angelleye Payment Gateway FOR Paypal ON WoocommerceAI | 21/9/2026 | 22/9/2026 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own… | |
| Aplazada | Media (5.3) | 0.38% | — | WT Stripe Payment Gateway Stripe FOR WoocommerceAI | 19/9/2026 | 21/9/2026 | The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only… | |
| Aplazada | Media (6.5) | 0.33% | — | PaymenterAI | 18/9/2026 | 24/9/2026 | Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pending service upgrade and later executes $credit->increment('amount', abs($price)) without DB::transaction or… | |
| Aplazada | Baja (3.7) | 0.14% | — | Robokassa Payment Gateway FOR WoocommerceAI | 17/9/2026 | 18/9/2026 | The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold… | |
| Aplazada | Crítica (10) | 0.50% | 💥 PoC | Cryptopayment GatewayAI | 13/9/2026 | 14/9/2026 | The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored… |