Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 396 respecto a la semana anterior
Críticas / altas1326▲ 43 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 468 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.23%—Ibtana Ecommerce Product AddonsAI19/9/202621/9/2026
The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaAlta (8.8)0.51%—Product Addons AND Product Options With Custom FieldsAI22/7/202622/7/2026
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any…
AplazadaCrítica (9.8)0.99%—Woocommerce Custom Product Addons PROAI24/3/202617/6/2026
The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_custom_formula() function within includes/process/price.php. This is due to insufficient sanitization and validation of…
AplazadaAlta (7.2)0.62%—Wpdesk Product Addons FOR WoocommerceAI18/2/202617/6/2026
The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 3.1.0. This is due to insufficient input validation of the 'operator' field in conditional logic rules within the evalConditions() function, which passes…
AplazadaMedia (6.5)0.21%—Vwthemes Ibtana Ecommerce Product AddonsAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana – Ecommerce Product Addons ibtana-ecommerce-product-addons allows DOM-Based XSS.This issue affects Ibtana – Ecommerce Product Addons: from n/a through <= 0.4.7.6.
ModificadaMedia (5.3)0.33%—Themeisle Product Addons & Fields FOR Woocommerce10/6/202417/6/2026
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Themeisle PPOM for WooCommerce allows Code Inclusion.This issue affects PPOM for WooCommerce: from n/a through 32.0.20.
ModificadaCrítica (9.8)1.4%—Themeisle Product Addons & Fields FOR Woocommerce26/4/202417/6/2026
The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ppom_upload_file function in all versions up to, and including, 32.0.18. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected…
ModificadaAlta (7.2)0.67%—Woocommerce Product Addons28/12/202317/6/2026
Deserialization of Untrusted Data vulnerability in WooCommerce Product Add-Ons.This issue affects Product Add-Ons: from n/a through 6.1.3.
ModificadaAlta (8.8)0.30%—Woocommerce Product Addons9/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Product Add-Ons plugin <= 6.1.3 versions.
ModificadaMedia (6.1)0.95%—Themeisle Product Addons & Fields FOR Woocommerce30/5/202317/6/2026
The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.
ModificadaMedia (4.8)0.46%—Themeisle Product Addons & Fields FOR Woocommerce15/5/202317/6/2026
The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.6 does not sanitize and escape some of its setting fields, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite…