Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
182 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.24% | — | Easy Paypal Stripe BUY NOW ButtonAI | 2/10/2026 | 2/10/2026 | The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase. | |
| Aplazada | Media (6.5) | 0.20% | — | Payment Plugins FOR Paypal WoocommerceAI | 23/9/2026 | 23/9/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, allowing unauthenticated attackers to have another buyer's approved but uncaptured… | |
| Aplazada | Media (5.3) | 0.16% | — | Angelleye Payment Gateway FOR Paypal ON WoocommerceAI | 21/9/2026 | 22/9/2026 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own… | |
| Aplazada | Media (5.9) | 0.23% | — | Paymentplugins Payment Plugins FOR Paypal WoocommerceAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's stored card to their own account and then charge or delete it. Exploitation requires… | |
| Aplazada | Media (5.3) | 0.34% | — | Payment Plugins FOR Paypal WoocommerceAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the secret that gates access to any order and, through it, that customer's billing and… | |
| Aplazada | Alta (8.7) | 0.43% | — | J2storeAIPaypalAI | 3/9/2026 | 3/9/2026 | Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The PayPal IPN listener's signature check (`_validateIPN()`) accepted `UNVERIFIED` and any non-`INVALID` response as valid, made its verification request… | |
| Analizada | Crítica (9.1) | 0.40% | — | Centarro Commerce Paypal | 2/9/2026 | 8/9/2026 | Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3. | |
| Aplazada | Media (6.5) | 0.33% | — | Contact Form 7 Paypal AND Stripe Add-onAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. | |
| Aplazada | Media (5.3) | 0.16% | — | Fullworksplugins Quick Paypal PaymentsAI | 12/8/2026 | 26/8/2026 | The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on an order-token match alone, so a buyer who pays an arbitrary small amount can have a full-price order marked paid. | |
| Aplazada | Media (5.3) | 0.32% | — | Payment Button FOR PaypalAI | 12/8/2026 | 26/8/2026 | The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers to create a real PayPal order against the merchant for an arbitrary lower amount. | |
| Aplazada | Media (5.3) | 0.16% | — | Paypal Payment Gateway FOR WoocommerceAI | 12/8/2026 | 26/8/2026 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the… | |
| Aplazada | Baja (3.7) | 0.24% | — | Accept Paypal Stripe With Subscriptions FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal… | |
| Aplazada | Media (5.3) | 0.29% | — | Accept Paypal Stripe With Subscriptions FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full… | |
| Aplazada | Alta (7.5) | 0.40% | — | Paymentplugins Payment Plugins FOR PaypalAI | 6/8/2026 | 26/8/2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpplugin Easy Paypal BUY NOW ButtonAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. | |
| Aplazada | Media (5.3) | 0.40% | — | Woocommerce Paypal PaymentsAI | 1/8/2026 | 29/9/2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing validation on a user controlled key. This… | |
| Aplazada | Media (6.5) | 0.22% | — | Accept Donations With Paypal AND StripeAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Payment Gateway FOR PaypalAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. | |
| Aplazada | Media (5.3) | 0.25% | — | Contact Form 7 Paypal Stripe ADD ONAI | 29/5/2026 | 21/7/2026 | The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correctly validates IPN authenticity by posting back to PayPal with… | |
| Aplazada | Alta (8.2) | 0.46% | — | Woocommerce Paypal PaymentsAI | 23/5/2026 | 23/7/2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an… | |
| Aplazada | Alta (8.2) | 0.60% | — | Easy Paypal Events TicketsAI | 4/5/2026 | 17/6/2026 | The Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains an information disclosure vulnerability in the QR code scanning endpoint that allows unauthenticated attackers to enumerate and retrieve all customer order records. Attackers can iterate over sequential WordPress post IDs through the… | |
| Aplazada | Alta (8.7) | 0.79% | — | Easy Paypal Events AND TicketsAI | 4/5/2026 | 17/6/2026 | Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains a hardcoded authentication bypass vulnerability in the QR code scanning functionality that allows unauthenticated remote attackers to bypass hash verification by supplying 'test' as the hash parameter. Attackers can access the vulnerable… | |
| Aplazada | Media (5.3) | 0.32% | — | Zealousweb Accept Paypal Payments Using Contact Form 7AI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in ZealousWeb Accept PayPal Payments using Contact Form 7 contact-form-7-paypal-extension allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept PayPal Payments using Contact Form 7: from n/a through <= 4.0.4. | |
| Aplazada | Media (5.3) | 0.29% | — | Paymentplugins Payment Plugins FOR Paypal WoocommerceAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Payment Plugins Payment Plugins for PayPal WooCommerce pymntpl-paypal-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Plugins for PayPal WooCommerce: from n/a through <= 2.0.13. | |
| Aplazada | Media (6.4) | 0.33% | — | Wordpress Paypal DonationAI | 21/3/2026 | 17/6/2026 | The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortcode in all versions up to, and including, 1.01. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'amount', 'email', 'title',… |