Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.7) | 0.14% | — | Robokassa Payment Gateway FOR WoocommerceAI | 17/9/2026 | 18/9/2026 | The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold… | |
| Aplazada | Media (6.5) | 0.33% | — | Robokassa Payment Gateway FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions. | |
| Aplazada | Media (5.3) | 0.16% | — | Paypal Payment Gateway FOR WoocommerceAI | 12/8/2026 | 26/8/2026 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the… | |
| Aplazada | Media (6.5) | 0.46% | — | Themehigh Stripe Payment Gateway FOR WoocommerceAI | 25/5/2026 | 24/7/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommerce allows Password Recovery Exploitation. This issue affects Stripe Payment Gateway for WooCommerce: from n/a through 5.0.7. | |
| Aplazada | Media (6.5) | 0.29% | — | Knitpay UPI QR Code Payment Gateway FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in knitpay UPI QR Code Payment Gateway for WooCommerce upi-qr-code-payment-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UPI QR Code Payment Gateway for WooCommerce: from n/a through <= 1.5.1. | |
| Aplazada | Alta (7.5) | 0.75% | 💥 Exploit | Bluesnap Payment Gateway FOR WoocommerceAI | 14/2/2026 | 17/6/2026 | The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.4.0. This is due to the plugin relying on WooCommerce's `WC_Geolocation::get_ip_address()` function to validate IPN requests, which trusts user-controllable headers like… | |
| Aplazada | Media (5.3) | 0.32% | — | Sumup Payment Gateway FOR WoocommerceAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in sumup SumUp Payment Gateway For WooCommerce sumup-payment-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SumUp Payment Gateway For WooCommerce: from n/a through <= 2.7.9. | |
| Aplazada | Media (6.5) | 0.25% | — | Onepay SRI Lanka Onepay Payment Gateway FOR WoocommerceAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Onepay Sri Lanka onepay Payment Gateway For WooCommerce onepay-payment-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects onepay Payment Gateway For WooCommerce: from n/a through <= 1.1.2. | |
| Aplazada | Alta (8.2) | 0.34% | — | Ipaymu Payment Gateway FOR WoocommerceAI | 7/1/2026 | 17/6/2026 | The iPaymu Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 2.0.2 via the 'check_ipaymu_response' function. This is due to the plugin not validating webhook request authenticity through signature verification or origin checks. This makes… | |
| Aplazada | Alta (7.1) | 0.24% | — | Robokassa Payment Gateway FOR WoocommerceAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robokassa Robokassa payment gateway for Woocommerce robokassa allows Reflected XSS.This issue affects Robokassa payment gateway for Woocommerce: from n/a through <= 1.8.6. | |
| Aplazada | Media (4.3) | 0.25% | — | Payrexx Payment Gateway FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in payrexx Payrexx Payment Gateway for WooCommerce woo-payrexx-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payrexx Payment Gateway for WooCommerce: from n/a through <= 3.1.5. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Coinpayments.net Payment Gateway FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CoinPayments CoinPayments.net Payment Gateway for WooCommerce coinpayments-payment-gateway-for-woocommerce allows Object Injection.This issue affects CoinPayments.net Payment Gateway for WooCommerce: from n/a through <= 1.0.17. | |
| Aplazada | Alta (7.1) | 0.39% | — | Codesolz Bitcoin Altcoin Payment Gateway FOR WoocommerceAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce woo-altcoin-payment-gateway allows Reflected XSS.This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through <= 1.7.6. | |
| Aplazada | Alta (7.1) | 0.36% | — | Fomopay Fomo PAY Chinese Payment SolutionAIFomopay Fomo-payment-gateway-for-woocommerceAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fomopay FOMO Pay Chinese Payment Solution fomo-payment-gateway-for-woocommerce allows Reflected XSS.This issue affects FOMO Pay Chinese Payment Solution: from n/a through <= 2.0.4. | |
| Aplazada | Crítica (9.3) | 0.50% | — | Codesolz Bitcoin Altcoin Payment Gateway FOR WoocommerceAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce woo-altcoin-payment-gateway allows Blind SQL Injection.This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through <= 1.7.6. | |
| Aplazada | Crítica (10) | 0.51% | — | Amin Omer Sudan Payment Gateway FOR WoocommerceAI | 29/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Sudan Payment Gateway for WooCommerce wc-sudan-payment-gateway allows Upload a Web Shell to a Web Server.This issue affects Sudan Payment Gateway for WooCommerce: from n/a through <= 1.2.2. | |
| Aplazada | Alta (7.1) | 0.29% | — | Robokassa Payment Gateway FOR WoocommerceAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robokassa Robokassa payment gateway for Woocommerce robokassa allows Reflected XSS.This issue affects Robokassa payment gateway for Woocommerce: from n/a through <= 1.6.1. | |
| Aplazada | Alta (7.5) | 0.45% | — | Hitpay Payment Solutions PTE LTD Hitpay Payment Gateway FOR WoocommerceAI | 13/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Payment Gateway for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects HitPay Payment Gateway for WooCommerce: from n/a through 4.1.3. | |
| Aplazada | Media (5.3) | 0.21% | — | Authorize NET Payment Gateway FOR WoocommerceAI | 4/6/2024 | 17/6/2026 | The Authorize.net Payment Gateway For WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 8.0. This is due to the plugin not properly verifying the authenticity of the request that updates a orders payment status. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (5.3) | 0.40% | — | 2checkout Payment Gateway FOR WoocommerceAI | 2/5/2024 | 17/6/2026 | The 2Checkout Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sniff_ins function in all versions up to, and including, 6.2. This makes it possible for unauthenticated attackers to make changes to orders and mark them as… | |
| Modificada | Crítica (9.8) | 0.90% | — | Coinmarketstats Bitcoin / Altcoin Payment Gateway FOR Woocommerce | 8/5/2023 | 17/6/2026 | The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users | |
| Modificada | Media (6.1) | 0.83% | — | Coinmarketstats Bitcoin / Altcoin Payment Gateway FOR Woocommerce | 4/10/2021 | 17/6/2026 | The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue |