PULSE
EN VIVO25señales / 24h
FEED
ransomqilin reclama a WellPerf · GB · Healthcareransomthegentlemen reclama a Sirl · PT · Not Foundransomthegentlemen reclama a Disney Family · US · Financial Servicesransomqilin reclama a Corporate 360 Business Solutions · CA · Professional Servicesransomqilin reclama a Assos Pharmaceuticals · TR · Healthcareransomqilin reclama a Cano Industrial · MX · Manufacturingransomqilin reclama a Triton Trading · PE · Financial Servicesransomqilin reclama a AppleOne Properties · PH · Not Foundransommoneymessage reclama a Indigo Energy · CA · Energyransomqilin reclama a Sunway Berhad · MY · Hospitality and Tourismransomkairos reclama a LR Reed · AU · Business Servicesransomnova reclama a VNSO · Not Foundransomblacknevas reclama a Zuni Shopping Center, Inc. · US · Consumer Servicesransomqilin reclama a P & A Construction · US · Constructionransomqilin reclama a WellPerf · GB · Healthcareransomthegentlemen reclama a Sirl · PT · Not Foundransomthegentlemen reclama a Disney Family · US · Financial Servicesransomqilin reclama a Corporate 360 Business Solutions · CA · Professional Servicesransomqilin reclama a Assos Pharmaceuticals · TR · Healthcareransomqilin reclama a Cano Industrial · MX · Manufacturingransomqilin reclama a Triton Trading · PE · Financial Servicesransomqilin reclama a AppleOne Properties · PH · Not Foundransommoneymessage reclama a Indigo Energy · CA · Energyransomqilin reclama a Sunway Berhad · MY · Hospitality and Tourismransomkairos reclama a LR Reed · AU · Business Servicesransomnova reclama a VNSO · Not Foundransomblacknevas reclama a Zuni Shopping Center, Inc. · US · Consumer Servicesransomqilin reclama a P & A Construction · US · Construction
← Todos los CVEs
CVE Watch23 jul 2026

CVE-2026-8904

The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vulnerable to Cross-Si

CVSS

4.3

Medio

EPSS

0.1%

p3

KEV

Exploit Today

1

0-100

Publicado: 9 jun 2026 · Última mod.: 23 jul 2026 · CWE-352

EPSS · 30d
0.1%EPSS · 30 días0.1%
2026-06-302026-07-23
Descripción técnica

The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the settingsPage function. This makes it possible for unauthenticated attackers to modify the plugin's settings, including toggling the webhook integration and changing the FastPicker and KDZ API URLs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-655407.1 ALT
0Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.2h
CVE-2026-655397.1 ALT
0Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.2h
CVE-2026-655366.5 MED
0Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.2h
CVE-2026-655125.4 MED
0Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions.2h
CVE-2026-654887.1 ALT
0Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.2h
CVE-2026-654719.6 CRÍ
0Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.2h