Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2509▼ 448 respecto a la semana anterior
Críticas / altas1286▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 464 respecto a la semana anterior
–

1844 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.9)0.20%—Imaginate-solutions File Uploads Addon FOR WoocommerceAI5/10/20265/10/2026
The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files.
RecibidaMedia (5.3)0.18%—Razorpay FOR WoocommerceAI4/10/20265/10/2026
The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.
RecibidaMedia (5.3)0.22%—Mailchimp FOR WoocommerceAI3/10/20263/10/2026
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart.
RecibidaMedia (4.3)0.16%—Helpdesk Support Ticket System FOR WoocommerceAI3/10/20263/10/2026
The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level…
RecibidaAlta (8.1)0.34%—Photo Reviews FOR WoocommerceAI3/10/20263/10/2026
The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta…
AplazadaAlta (7.2)0.24%—Cusrev Customer Reviews FOR WoocommerceAI2/10/20262/10/2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaMedia (6.5)0.31%—DC Woocommerce Multi VendorAI2/10/20263/10/2026
The Dc Woocommerce Multi Vendor plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter of the /multivendorx/v1/compliance/report-abuse REST endpoint in versions up to and including 5.0.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
AplazadaMedia (5.3)0.26%—Webtoffee Gift Cards FOR WoocommerceAI2/10/20262/10/2026
The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations…
AplazadaAlta (7.2)0.37%—Hide Shipping Method FOR WoocommerceAI1/10/20261/10/2026
Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions.
AplazadaAlta (7.5)0.30%—Photo Reviews FOR WoocommerceAI1/10/20261/10/2026
Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.
AplazadaAlta (7.2)0.28%—PDF Invoices Packing Slips FOR WoocommerceAI1/10/20261/10/2026
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaMedia (5.3)0.22%—WP Hosting AS PAY With Vipps FOR WoocommerceAI30/9/202630/9/2026
Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.4.
AplazadaMedia (5.4)0.10%—Razorpay Payment Links FOR WoocommerceAI30/9/202630/9/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.
AplazadaMedia (6.5)0.13%—Yith Woocommerce TAB ManagerAI30/9/202630/9/2026
Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.
AplazadaAlta (7.6)0.28%—Quanticedgesolutions Category Discount WoocommerceAI30/9/202630/9/2026
Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.
AplazadaAlta (7.5)0.32%—Cusrev Customer Reviews FOR WoocommerceAI30/9/202630/9/2026
Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
AplazadaAlta (7.1)0.18%—Trusted Shops Easy Integration FOR WoocommerceAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.
AplazadaAlta (7.1)0.18%—Yithemes Yith Woocommerce Ajax SearchAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.
AplazadaAlta (7.2)0.40%—Kadencewp Kadence Woocommerce Email DesignerAI30/9/202630/9/2026
Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.
AplazadaAlta (7.2)0.37%—Wpfactory Cost OF Goods FOR WoocommerceAI30/9/202630/9/2026
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
AplazadaAlta (7.2)0.37%—Minimum AND Maximum Quantity FOR WoocommerceAI30/9/202630/9/2026
Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.
AplazadaAlta (7.2)0.37%—Music Player FOR WoocommerceAI30/9/202630/9/2026
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
AplazadaMedia (5.4)0.17%—Blacklist Manager FOR WoocommerceAI28/9/202628/9/2026
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
AplazadaMedia (5.3)0.24%—Mailchimp FOR WoocommerceAI27/9/202628/9/2026
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the…
AplazadaCrítica (9.8)0.41%—Afrfq Request A Quote FOR WoocommerceAI26/9/202628/9/2026
The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied…