Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
3234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.30% | — | Photo Reviews FOR WoocommerceAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions. | |
| Aplazada | Alta (7.2) | 0.28% | — | PDF Invoices Packing Slips FOR WoocommerceAI | 1/10/2026 | 1/10/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.22% | — | WP Hosting AS PAY With Vipps FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.4. | |
| Aplazada | Media (5.4) | 0.10% | — | Razorpay Payment Links FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions. | |
| Aplazada | Media (6.5) | 0.13% | — | Yith Woocommerce TAB ManagerAI | 30/9/2026 | 30/9/2026 | Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions. | |
| Aplazada | Alta (7.6) | 0.28% | — | Quanticedgesolutions Category Discount WoocommerceAI | 30/9/2026 | 30/9/2026 | Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Cusrev Customer Reviews FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. | |
| Aplazada | Alta (8.2) | 0.36% | — | MakecommerceAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Trusted Shops Easy Integration FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | WOO Commerce Product Table LiteAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Yithemes Yith Woocommerce Ajax SearchAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Implecode Ecommerce Product CatalogAI | 30/9/2026 | 30/9/2026 | Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. | |
| Aplazada | Alta (7.2) | 0.40% | — | Kadencewp Kadence Woocommerce Email DesignerAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Wpfactory Cost OF Goods FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Minimum AND Maximum Quantity FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Music Player FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. | |
| Aplazada | Alta (8.8) | 0.28% | — | Verge3d Publishing AND E CommerceAI | 30/9/2026 | 30/9/2026 | The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the… | |
| Pendiente de análisis | Media (6.9) | 0.39% | — | Marcos Camara01 Ecommerce TemplateAI | 28/9/2026 | 29/9/2026 | Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The… | |
| Aplazada | Media (5.4) | 0.17% | — | Blacklist Manager FOR WoocommerceAI | 28/9/2026 | 28/9/2026 | The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded. | |
| Aplazada | Media (5.3) | 0.21% | — | Verge3d Publishing AND E CommerceAI | 27/9/2026 | 28/9/2026 | The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization. | |
| Aplazada | Media (5.3) | 0.24% | — | Mailchimp FOR WoocommerceAI | 27/9/2026 | 28/9/2026 | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the… | |
| Aplazada | Crítica (9.8) | 0.41% | — | Afrfq Request A Quote FOR WoocommerceAI | 26/9/2026 | 28/9/2026 | The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied… | |
| Aplazada | Crítica (9.1) | 0.39% | — | Cusrev Customer Reviews FOR WoocommerceAI | 25/9/2026 | 25/9/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete… | |
| Aplazada | Media (6.5) | 0.17% | — | Custom Thank YOU Page FOR WoocommerceAI | 24/9/2026 | 24/9/2026 | The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to export or reset(delete) the… | |
| Aplazada | Media (6.5) | 0.28% | — | Yith Woocommerce Request A QuoteAI | 23/9/2026 | 23/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n/a before 4.46.1. |