Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

124 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.35%—Payment Gateway FOR PaypalAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
AplazadaMedia (6.5)0.27%—Payplus Payment GatewayAI20/7/202621/7/2026
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses.
AplazadaMedia (5.3)0.29%—Payplus Payment GatewayAI20/7/202621/7/2026
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders.
AplazadaAlta (7.2)0.56%—Corvuspay Woocommerce Payment GatewayAI11/7/202613/7/2026
The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
AplazadaMedia (5.3)0.47%—Corvuspay Woocommerce Payment GatewayAI9/7/20269/7/2026
The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to cancel any…
AplazadaCrítica (9.8)0.56%—Novalnet Payment GatewayAI2/7/20262/7/2026
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
AplazadaAlta (7.2)0.43%—Algoritmika Custom Payment Gateways FOR WoocommerceAI1/7/20261/7/2026
The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alg_wc_cpg_input_fields' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
AplazadaMedia (6.5)0.17%—Funnelkit Payment Gateway FOR Stripe WoocommerceAI26/6/202629/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions.
AplazadaMedia (6.5)0.33%—Woocart Payment Gateway Based Fees AND Discounts FOR WoocommerceAI26/6/202629/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.
AplazadaAlta (7.5)0.43%—Corvuspay Woocommerce Payment GatewayAI26/6/202626/6/2026
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
AplazadaMedia (5.4)0.29%—UPI QR Code Payment GatewayAI25/6/202625/6/2026
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
AplazadaMedia (6.5)0.40%—Woocommerce Stripe Payment GatewayAI16/6/202617/6/2026
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment…
AplazadaAlta (7.5)0.42%—Conekta Payment GatewayAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.
AplazadaAlta (7.5)0.42%—Idpay Payment GatewayAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.
AplazadaMedia (6.5)0.46%—Themehigh Stripe Payment Gateway FOR WoocommerceAI25/5/202624/7/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommerce allows Password Recovery Exploitation. This issue affects Stripe Payment Gateway for WooCommerce: from n/a through 5.0.7.
AplazadaMedia (5.3)0.29%—Linknacional Payment Gateway PIX FOR GivewpAI13/3/202617/6/2026
Missing Authorization vulnerability in linknacional Payment Gateway Pix For GiveWP payment-gateway-pix-for-givewp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway Pix For GiveWP: from n/a through <= 2.2.3.
AplazadaMedia (6.5)0.29%—Knitpay UPI QR Code Payment Gateway FOR WoocommerceAI20/2/202617/6/2026
Missing Authorization vulnerability in knitpay UPI QR Code Payment Gateway for WooCommerce upi-qr-code-payment-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UPI QR Code Payment Gateway for WooCommerce: from n/a through <= 1.5.1.
AplazadaAlta (7.5)0.75%💥 ExploitBluesnap Payment Gateway FOR WoocommerceAI14/2/202617/6/2026
The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.4.0. This is due to the plugin relying on WooCommerce's `WC_Geolocation::get_ip_address()` function to validate IPN requests, which trusts user-controllable headers like…
AplazadaMedia (4.9)0.38%—Sibs Woocommerce Payment GatewayAI4/2/202617/6/2026
The SIBS woocommerce payment gateway plugin for WordPress is vulnerable to time-based SQL Injection via the ‘referencedId’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaMedia (5.3)0.32%—Chapa Payment GatewayAI4/2/202617/6/2026
The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.3 via 'chapa_proceed' WooCommerce API endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including the merchant's Chapa…
AplazadaMedia (5.3)0.32%—Sumup Payment Gateway FOR WoocommerceAI23/1/202617/6/2026
Missing Authorization vulnerability in sumup SumUp Payment Gateway For WooCommerce sumup-payment-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SumUp Payment Gateway For WooCommerce: from n/a through <= 2.7.9.
AplazadaMedia (6.5)0.25%—Onepay SRI Lanka Onepay Payment Gateway FOR WoocommerceAI22/1/202617/6/2026
Missing Authorization vulnerability in Onepay Sri Lanka onepay Payment Gateway For WooCommerce onepay-payment-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects onepay Payment Gateway For WooCommerce: from n/a through <= 1.1.2.
AplazadaMedia (6.5)0.44%—Cardpaysolutions Payment Gateway Authorize NET CIM FOR WoocommerceAI22/1/202617/6/2026
Missing Authorization vulnerability in cardpaysolutions Payment Gateway Authorize.Net CIM for WooCommerce authnet-cim-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway Authorize.Net CIM for WooCommerce: from n/a through <= 2.1.2.
AplazadaMedia (5.3)0.26%—Float Payment GatewayAI14/1/202617/6/2026
The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error handling in the verifyFloatResponse() function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to mark any WooCommerce order as failed.
AplazadaMedia (5.3)0.26%—Aplazo Payment GatewayAI14/1/202617/6/2026
The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_success_response() function in all versions up to, and including, 1.4.3. This makes it possible for unauthenticated attackers to set any WooCommerce order to `pending…
Orbitaley — Vulnerabilidades