Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2543▼ 416 respecto a la semana anterior
Críticas / altas1316▲ 27 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.24% | — | Premium PackagesAI | 25/9/2026 | 25/9/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (5.3) | 0.20% | — | Premium PackagesAI | 23/9/2026 | 23/9/2026 | The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment confirmations and subscription-cancellation events against any order whose transaction id they know. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpdownloadmanager Wpdm Premium PackagesAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | Premium PackagesAI | 16/8/2026 | 26/8/2026 | The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and… | |
| Aplazada | Alta (7.5) | 0.51% | — | Wpdmpp Premium PackagesAI | 28/7/2026 | 28/7/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint in versions up to, and including, 6.2.0. This is due to insufficient escaping on the user-supplied parameter, which is… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wpdm Premium PackagesAI | 23/7/2026 | 23/7/2026 | Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Wpdm Premium PackagesAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. | |
| Aplazada | Media (6.5) | 0.47% | — | Premium Packages Sell Digital Products SecurelyAI | 23/7/2026 | 23/7/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Aplazada | Media (6.3) | 0.58% | — | Premium PackagesAI | 23/7/2026 | 23/7/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function — hooked to the unauthenticated WordPress `wp` action — decoding the attacker-controlled… | |
| Aplazada | Media (4.3) | 0.13% | — | Shahjada Wpdm-premium-packagesAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages allows Cross Site Request Forgery.This issue affects WPDM – Premium Packages: from n/a through <= 6.0.2. | |
| Aplazada | Media (6.5) | 0.25% | — | Shahjada Wpdm-premium-packagesAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages allows Stored XSS.This issue affects WPDM – Premium Packages: from n/a through <= 6.0.6. | |
| Aplazada | Alta (7.6) | 0.97% | — | Shahjada Wpdm-premium-packagesAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages allows Blind SQL Injection.This issue affects WPDM – Premium Packages: from n/a through <= 5.9.6. | |
| Aplazada | Media (6.1) | 0.52% | — | Premium Packages Sell Digital Products SecurelyAI | 22/11/2024 | 17/6/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.9.3. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.4) | 0.55% | — | Premium Packages Sell Digital Products SecurelyAI | 21/11/2024 | 17/6/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdmpp_pay_link shortcode in all versions up to, and including, 5.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Modificada | Alta (7.2) | 0.46% | — | Wpdownloadmanager Premium Packages - Sell Digital Products Securely | 18/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages.This issue affects WPDM – Premium Packages: from n/a through <= 6.0.5. | |
| Analizada | Media (4.3) | 0.18% | — | Wpdownloadmanager Premium Packages - Sell Digital Products Securely | 25/9/2024 | 17/6/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. This is due to missing nonce validation on the addRefund() function. This makes it possible for unauthenticated attackers to perform actions such as… | |
| Aplazada | Alta (7.1) | 0.35% | — | W3 Eden INC Premium PackagesAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Premium Packages allows Reflected XSS.This issue affects Premium Packages: from n/a through 5.8.2. | |
| Modificada | Media (6.5) | 0.99% | — | Wpdownloadmanager Premium Packages - Sell Digital Products Securely | 12/8/2023 | 17/6/2026 | The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a… |