Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
401 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.29% | — | 10web Social Photo FeedAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions. | |
| Aplazada | Alta (7.2) | 0.40% | — | Rymera WEB CO WOO Product Feed PROAI | 5/10/2026 | 6/10/2026 | Deserialization of Untrusted Data vulnerability in Rymera Web Co Product Feed PRO for WooCommerce woo-product-feed-pro allows Object Injection.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.5.7. | |
| Aplazada | Alta (7.2) | 0.27% | — | Smashballoon Social Post FeedAI | 2/10/2026 | 3/10/2026 | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message via v-html in Admin Builder Preview in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Alta (7.2) | 0.32% | — | CTX Feed PROAI | 2/10/2026 | 3/10/2026 | The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input validation on the 'Feed Config' field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with Administrator-level… | |
| Aplazada | Crítica (9.3) | 0.99% | 💥 PoC | GmfeedAI | 29/9/2026 | 30/9/2026 | Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the lack of… | |
| Aplazada | Media (6.8) | 0.24% | — | Etruel Wpematico RSS Feed FetcherAI | 27/9/2026 | 28/9/2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (4.1) | 0.18% | — | Etruel Wpematico RSS Feed FetcherAI | 27/9/2026 | 28/9/2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back. | |
| Aplazada | Media (4.9) | 0.19% | — | Etruel Wpematico RSS Feed FetcherAI | 27/9/2026 | 28/9/2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an… | |
| Aplazada | Media (4.1) | 0.18% | — | Etruel Wpematico RSS Feed FetcherAI | 27/9/2026 | 28/9/2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the… | |
| Aplazada | Media (6.8) | 0.24% | — | Etruel Wpematico RSS Feed FetcherAI | 24/9/2026 | 24/9/2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the session of any… | |
| Aplazada | Baja (2.7) | 0.22% | — | Wpecom Wpeomatico RSS Feed FetcherAI | 24/9/2026 | 24/9/2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the configuration and execution logs of campaigns created by other users, including… | |
| Aplazada | Media (6.8) | 0.24% | — | Wpematico RSS Feed FetcherAI | 24/9/2026 | 24/9/2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contributors to perform Stored Cross-Site Scripting attacks against higher-privileged users who review the campaign. | |
| Aplazada | Media (4.9) | 1.1% | — | CTX FeedAI | 22/9/2026 | 22/9/2026 | The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.6.43 via the 'provider' parameter. This makes it possible for authenticated attackers, with shop manager-level access and… | |
| Aplazada | Media (6.4) | 0.41% | — | Smashballoon Custom Twitter FeedsAI | 18/9/2026 | 18/9/2026 | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (8.5) | 0.36% | — | Product Feed ManagerAI | 17/9/2026 | 17/9/2026 | Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Private Feed KEYAI | 17/9/2026 | 18/9/2026 | The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators. | |
| Aplazada | Media (4.9) | 0.33% | — | Product XML Feed ManagerAI | 12/9/2026 | 14/9/2026 | The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that… | |
| Aplazada | Media (6.5) | 0.26% | — | Wpmr Google Feed Manager FOR WoocommerceAI | 9/9/2026 | 9/9/2026 | The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnerable to time-based SQL Injection via the 'feed' parameter in all versions up to, and including, 2.23.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Aplazada | Alta (7.1) | 0.35% | — | Pixelyoursite EDD Product Catalog FeedAI | 8/9/2026 | 8/9/2026 | The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the wpeddpcf_delete_feed function in all versions up to, and including, 1.0.2. This makes it possible for authenticated… | |
| Aplazada | Media (6.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 5/9/2026 | 8/9/2026 | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who… | |
| Aplazada | Alta (8.2) | 0.20% | — | Wp-feedstats Wordpress PluginAI | 2/9/2026 | 3/9/2026 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc | |
| Aplazada | Alta (7.5) | 0.39% | — | Surefeedback Client SiteAI | 27/8/2026 | 28/8/2026 | Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions. | |
| Aplazada | Alta (8.8) | 0.69% | — | Etruel Wpematico RSS Feed FetcherAI | 22/8/2026 | 24/8/2026 | The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.9) | 0.47% | — | CTX FeedAI | 18/8/2026 | 20/8/2026 | Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions. | |
| Aplazada | Media (6.4) | 0.33% | — | Smashballoon Social Post FeedAI | 16/8/2026 | 20/8/2026 | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Shortcode Attribute in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… |