Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

123 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.1)——Tomlister Payflex Payment GatewayAI6/10/20266/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1.
RecibidaMedia (5.3)——Deema Payment GatewayAI6/10/20266/10/2026
The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status or amount, allowing unauthenticated users to have orders marked as paid without any payment being taken.
RecibidaMedia (5.3)——Deema Payment GatewayAI6/10/20266/10/2026
The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing unauthenticated attackers to mark an unpaid order as paid, or to cancel or refund an existing order.
RecibidaMedia (5.3)0.18%—UPI QR Code Payment GatewayAI5/10/20265/10/2026
The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment.
AplazadaMedia (5.3)0.18%—Paytm Payment GatewayAI2/10/20262/10/2026
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders,…
AplazadaAlta (7.5)0.18%—Paytm Payment GatewayAI1/10/20261/10/2026
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection…
AplazadaAlta (7.5)0.22%—Paytm Payment GatewayAI1/10/20261/10/2026
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts…
AplazadaMedia (6.5)0.25%—Conekta Payment GatewayAI23/9/202623/9/2026
Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
AplazadaMedia (6.5)0.19%—Payplus Payment GatewayAI23/9/202623/9/2026
Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.
AplazadaMedia (5.3)0.18%—Sumit Payment GatewayAI23/9/202624/9/2026
The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment.
AplazadaMedia (5.3)0.16%—Angelleye Payment Gateway FOR Paypal ON WoocommerceAI21/9/202622/9/2026
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own…
AplazadaMedia (5.3)0.38%—WT Stripe Payment Gateway Stripe FOR WoocommerceAI19/9/202621/9/2026
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only…
AplazadaBaja (3.7)0.14%—Robokassa Payment Gateway FOR WoocommerceAI17/9/202618/9/2026
The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold…
AplazadaCrítica (10)0.50%—Cryptopayment GatewayAI13/9/202614/9/2026
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored…
AplazadaMedia (5.9)0.16%—Payment Gateway PaypayAI11/9/202611/9/2026
The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as paid, or to cancel or fail them.
AplazadaMedia (6.5)0.33%—Robokassa Payment Gateway FOR WoocommerceAI10/9/202610/9/2026
Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.
AplazadaMedia (5.3)0.16%—Epayco Payment GatewayAI4/9/20268/9/2026
The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.
AplazadaMedia (5.3)0.33%—Conekta Payment GatewayAI22/8/202626/8/2026
The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.
AplazadaMedia (6.5)0.42%—Piraeus Bank Woocommerce Payment GatewayAI18/8/202620/8/2026
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
AplazadaAlta (7.5)0.42%—Duitku Payment GatewayAI18/8/202620/8/2026
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
AplazadaAlta (7.5)0.35%—Clink Bitcoin Lightning Payment GatewayAI13/8/202614/8/2026
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
AplazadaMedia (5.3)0.16%—Paypal Payment Gateway FOR WoocommerceAI12/8/202626/8/2026
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the…
AplazadaAlta (7.5)0.19%—Redyx Payment Gateway FOR Redsys AND Woocommerce LiteAI6/8/202626/8/2026
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own…
AplazadaAlta (7.5)0.36%—Clover Payment Gateway BY ZaytechAI27/7/202627/7/2026
The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by…
AplazadaAlta (7.5)0.35%—Payment Gateway FOR PaypalAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.