Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.29% | — | Wp-ecommerce WP EcommerceAI | 11/2/2026 | 17/6/2026 | The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog. | |
| Aplazada | Media (5.9) | 0.18% | — | Wp-ecommerce Recurring Paypal DonationsAI | 22/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce Recurring PayPal Donations recurring-donation allows Stored XSS.This issue affects Recurring PayPal Donations: from n/a through <= 1.8. | |
| Aplazada | Alta (7.1) | 0.34% | — | Perfectsolution WP Ecommerce QuickpayAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PerfectSolution WP eCommerce Quickpay wp-ecommerce-quickpay allows Reflected XSS.This issue affects WP eCommerce Quickpay: from n/a through <= 1.1.0. | |
| Modificada | Baja (2.7) | 0.33% | — | Wp-ecommerce Easy WP Smtp | 13/6/2024 | 17/6/2026 | The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.3.0. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings. This makes it possible for authenticated… | |
| Analizada | Media (5.4) | 0.25% | — | Wp-ecommerce Recurring Paypal Donations | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpecommerce Recurring PayPal Donations allows Stored XSS.This issue affects Recurring PayPal Donations: from n/a through 1.7. | |
| Modificada | Media (5.3) | 0.42% | — | ZAO WP Ecommerce | 28/2/2024 | 17/6/2026 | The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all versions up to, and including, 3.15.1. This makes it possible for unauthenticated attackers to create arbitrary posts with arbitrary content. | |
| Modificada | Alta (7.5) | 0.72% | — | Wp-ecommerce WP Ecommerce | 28/2/2024 | 17/6/2026 | The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Crítica (9.8) | 4.5% | — | Wp-ecommerce Easy WP Smtp | 7/6/2023 | 17/6/2026 | The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings… | |
| Modificada | Alta (8.8) | 1.4% | — | Wp-ecommerce Easy WP Smtp | 6/12/2022 | 17/6/2026 | Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress. | |
| Modificada | Media (6.5) | 0.79% | — | Wp-ecommerce Easy WP Smtp | 6/12/2022 | 17/6/2026 | Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress. | |
| Modificada | Alta (8.1) | 0.86% | — | Wp-ecommerce Easy WP Smtp | 6/12/2022 | 17/6/2026 | Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress. | |
| Modificada | Alta (7.2) | 1.2% | — | Wp-ecommerce Easy WP Smtp | 31/10/2022 | 17/6/2026 | The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. | |
| Modificada | Alta (7.5) | 65% | — | Wp-ecommerce Easy WP Smtp | 14/12/2020 | 17/6/2026 | The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links.… | |
| Modificada | Media (6.1) | 0.78% | — | Wp-ecommerce Easy WP Smtp | 24/4/2017 | 17/6/2026 | XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body. | |
| Modificada | Alta (7.5) | 2.7% | — | Wpshopstyling Wp-ecommerce-shop-styling | 27/5/2014 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPress before 1.8 allows remote attackers to execute arbitrary PHP code via a URL in the dompdf parameter. |