Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.11% | — | Paymob FOR WoocommerceAI | 23/9/2026 | 23/9/2026 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce orders as paid without any payment. | |
| Aplazada | Media (4.7) | 0.17% | — | Paymob FOR WoocommerceAI | 23/9/2026 | 23/9/2026 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX actions that manage its payment-gateway configuration, allowing users with contributor-level access to delete, wipe, or modify that configuration, including the stored payment credentials. | |
| Aplazada | Media (5.3) | 0.20% | — | Paymob FOR WoocommerceAI | 23/9/2026 | 23/9/2026 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers to write a card-token record to any user's account and to enumerate registered accounts. | |
| Aplazada | Alta (7.1) | 0.25% | — | Paymob FOR WoocommerceAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions. | |
| Aplazada | Alta (8.6) | 0.45% | — | Paymob FOR WoocommerceAI | 14/8/2026 | 26/8/2026 | The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to… | |
| Aplazada | Alta (7.5) | 0.35% | — | Paymob FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions. |