Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.22% | — | Wpeasycart WP EasycartAI | 23/9/2026 | 23/9/2026 | Contributor SQL Injection in WP EasyCart <= 5.9.4 versions. | |
| Aplazada | Alta (7.2) | 0.43% | — | Wpeasycart WP EasycartAI | 9/9/2026 | 9/9/2026 | The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX handler iterating over every $_POST key and passing it directly into update_option() without any allowlist, while gating the handler only on… | |
| Aplazada | Alta (8.5) | 0.36% | — | Wpeasycart WP EasycartAI | 2/7/2026 | 2/7/2026 | Contributor SQL Injection in WP EasyCart <= 5.9.0 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Levelfourdevelopment WP EasycartAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Blind SQL Injection.This issue affects WP EasyCart: from n/a through <= 5.8.13. | |
| Aplazada | Media (5.3) | 0.29% | — | Levelfourdevelopment WP EasycartAI | 9/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Retrieve Embedded Sensitive Data.This issue affects WP EasyCart: from n/a through <= 5.8.11. | |
| Aplazada | Media (5.3) | 0.38% | — | Wpeasycart WP EasycartAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19. | |
| Aplazada | Media (5.4) | 0.21% | — | Wpeasycart WP EasycartAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19. | |
| Modificada | Alta (7.2) | 0.70% | — | Wpeasycart WP Easycart | 12/7/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in versions up to, and including, 5.4.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Modificada | Media (4.3) | 0.24% | — | Wpeasycart WP Easycart | 9/6/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_duplicate_product function. This makes it possible for unauthenticated attackers to duplicate products via a forged request… | |
| Modificada | Media (4.3) | 0.24% | — | Wpeasycart WP Easycart | 9/6/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_activate_product function. This makes it possible for unauthenticated attackers to bulk activate products via a forged… | |
| Modificada | Media (4.3) | 0.24% | — | Wpeasycart WP Easycart | 9/6/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_deactivate_product function. This makes it possible for unauthenticated attackers to bulk deactivate products via a forged… | |
| Modificada | Media (4.3) | 0.24% | — | Wpeasycart WP Easycart | 9/6/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_deactivate_product function. This makes it possible for unauthenticated attackers to deactivate products via a forged request… | |
| Modificada | Media (4.3) | 0.23% | — | Wpeasycart WP Easycart | 9/6/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_delete_product function. This makes it possible for unauthenticated attackers to bulk delete products via a forged request… | |
| Modificada | Media (4.3) | 0.24% | — | Wpeasycart WP Easycart | 9/6/2023 | 17/6/2026 | The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_delete_product function. This makes it possible for unauthenticated attackers to delete products via a forged request granted… | |
| Modificada | Alta (7.2) | 1.1% | — | Wpeasycart WP Easycart | 3/4/2023 | 17/6/2026 | The Shopping Cart & eCommerce Store WordPress plugin before 5.4.3 does not validate HTTP requests, allowing authenticated users with admin privileges to perform LFI attacks. | |
| Modificada | Alta (8.8) | 19% | — | Wpeasycart WP Easycart | 6/10/2017 | 17/6/2026 | The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain administrator privileges and execute arbitrary code via the option_name and option_value parameters. | |
| Modificada | Media (6.5) | 51% | — | Wpeasycart WP Easycart | 15/1/2015 | 17/6/2026 | Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin before 3.0.9 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the… | |
| Modificada | Media (5) | 4.5% | — | Levelfourdevelopment Wp-easycart | 11/7/2014 | 17/6/2026 | The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls the phpinfo function. |