Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.22% | — | Mailchimp FOR WoocommerceAI | 3/10/2026 | 6/10/2026 | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart. | |
| Aplazada | Media (5.3) | 0.24% | — | Mailchimp FOR WoocommerceAI | 27/9/2026 | 28/9/2026 | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the… | |
| Aplazada | Media (5.3) | 0.30% | — | Mailchimp FOR WoocommerceAI | 19/9/2026 | 21/9/2026 | The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change. | |
| Aplazada | Alta (7.6) | 0.38% | — | Mailchimp FOR WoocommerceAI | 13/8/2026 | 14/8/2026 | Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. | |
| Modificada | Baja (2.7) | 0.77% | — | Mailchimp FOR Woocommerce | 29/8/2022 | 17/6/2026 | The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example | |
| Modificada | Media (4.3) | 0.71% | — | Mailchimp FOR Woocommerce | 29/8/2022 | 17/6/2026 | The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for… |