Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.34% | — | Wpswings Wallet System FOR WoocommerceAI | 12/8/2026 | 26/8/2026 | The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero, and complete checkout without paying the… | |
| Aplazada | Media (5.9) | 0.29% | — | Weblizar Points AND Rewards FOR WoocommerceAIWeblizar Wallet System FOR WoocommerceAI | 30/7/2026 | 30/7/2026 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily… | |
| Aplazada | Alta (7.1) | 0.34% | — | Wpswings Wallet System FOR WoocommerceAI | 29/6/2026 | 29/6/2026 | Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions. | |
| Aplazada | Alta (7.1) | 0.37% | — | Wpswings Wallet System FOR WoocommerceAI | 2/6/2026 | 22/7/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System for WooCommerce: from n/a through 2.7.5. | |
| Aplazada | Media (6.5) | 0.25% | — | Wpswings Wallet System FOR WoocommerceAI | 17/1/2026 | 17/6/2026 | The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'change_wallet_fund_request_status_callback' function in all versions up to, and including, 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (6.3) | 0.20% | — | Wpswings Wallet System FOR WoocommerceAI | 5/1/2026 | 7/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for WooCommerce: from n/a through <= 2.7.3. | |
| Aplazada | Media (4.3) | 0.14% | — | Wpswings Wallet System FOR WoocommerceAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Cross Site Request Forgery.This issue affects Wallet System for WooCommerce: from n/a through <= 2.6.7. | |
| Aplazada | Alta (7.1) | 0.29% | — | Wpswings Wallet System FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Reflected XSS.This issue affects Wallet System for WooCommerce: from n/a through <= 2.6.8. | |
| Analizada | Media (4.3) | 0.25% | — | Wpswings Wallet System FOR Woocommerce | 4/3/2025 | 17/6/2026 | The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 2.6.2. This makes it possible for unauthenticated attackers to increase their own wallet balance,… | |
| Analizada | Media (4.3) | 0.15% | — | Wpswings Wallet System FOR Woocommerce | 4/3/2025 | 17/6/2026 | The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation in class-wallet-user-table.php. This makes it… | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpswings Wallet System FOR WoocommerceAI | 13/8/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wallet System for WooCommerce: from n/a through 2.5.13. | |
| Aplazada | Media (5.4) | 0.21% | — | Wpswings Wallet System FOR WoocommerceAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce.This issue affects Wallet System for WooCommerce: from n/a through 2.5.9. |