Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
721 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.39% | — | Wpsocialrocket Social Rocket | 7/1/2025 | 17/6/2026 | The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tweet_settings_save() and tweet_settings_update() functions in all versions up to, and including, 1.3.4. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.1) | 0.19% | — | WP Social Autoconnect Project WP Social Autoconnect | 4/1/2025 | 17/6/2026 | The WP Social AutoConnect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted… | |
| Aplazada | Media (4.3) | 0.42% | — | Repuso Social-testimonials-and-reviews-widgetAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso social-testimonials-and-reviews-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social proof testimonials and reviews by Repuso: from n/a through <= 4.97. | |
| Aplazada | Alta (7.1) | 0.26% | — | Lemonadestudio Lemonade Social Networks Autoposter PinterestAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lemonadestudio Lemonade Social Networks Autoposter Pinterest lemonade-sna-pinterest-edition allows Reflected XSS.This issue affects Lemonade Social Networks Autoposter Pinterest: from n/a through <= 2.0. | |
| Aplazada | Alta (8.9) | 0.58% | — | SocialstreamAILaravel JetstreamAILaravel SocialiteAI | 20/12/2024 | 17/6/2026 | Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffolding provided by Laravel Jetstream, with scaffolding that has support for Laravel Socialite. When linking a social account to an already authenticated user, the lack of a confirmation step… | |
| Aplazada | Alta (7.1) | 0.21% | — | Jesse Overright Social Media SharingAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jesse Overright Social Media Sharing social-media-sharing allows Stored XSS.This issue affects Social Media Sharing: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.21% | — | ECT Social ShareAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in etemplates ECT Social Share ect-social-share allows Stored XSS.This issue affects ECT Social Share: from n/a through <= 1.3. | |
| Modificada | Media (4.3) | 0.73% | — | Heateor Super Socializer | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Team Heateor Super Socializer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Socializer: from n/a through 7.13.54. | |
| Aplazada | Media (5.3) | 0.55% | — | Wisernotify Wiser Notify Social ProofAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Wiser Notify WiserNotify Social Proof allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WiserNotify Social Proof: from n/a through 2.5. | |
| Aplazada | Media (4.3) | 0.35% | — | Social Share PRO Social Share Icons AND Social Share ButtonsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in social share pro Social Share Icons & Social Share Buttons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.5.7. | |
| Aplazada | Media (4.3) | 0.47% | — | Inisev Social Media & Share IconsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Media & Share Icons: from n/a through 2.8.1. | |
| Aplazada | Media (4.3) | 0.42% | — | Cybernetikz Easy Social IconsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in cybernetikz Easy Social Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Icons: from n/a through 3.2.5. | |
| Aplazada | Media (6.4) | 0.36% | — | Social Media ShortcodesAI | 12/12/2024 | 17/6/2026 | The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'patreon' shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.41% | — | Sharethis Social Media FeatherAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in socialmediafeather Social Media Feather social-media-feather allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Media Feather: from n/a through <= 2.1.3. | |
| Modificada | Media (4.3) | 0.42% | — | Easysocialfeed Easy Social Feed | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Sajid Javed Easy Social Feed easy-facebook-likebox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Feed: from n/a through <= 6.5.1. | |
| Aplazada | Media (5.3) | 0.43% | — | Acato Branded Social ImagesAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Acato Branded Social Images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Branded Social Images: from n/a through 1.1.0. | |
| Aplazada | Media (5.3) | 0.76% | — | Miniorange Wordpress Social Login AND RegisterAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.0. | |
| Aplazada | Baja (3.5) | 0.44% | — | Miniorange Wordpress Social LoginAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.5.14. | |
| Aplazada | Media (6.4) | 0.26% | — | Codemshop Social TalkAI | 7/12/2024 | 17/6/2026 | The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'msntt_add_plus_talk' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (4.8) | 0.31% | — | Sanil Sticky Social Icons | 6/12/2024 | 17/6/2026 | The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.9) | 0.29% | — | Sanil Sticky Social IconsAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sanil Shakya Sticky Social Icons sticky-social-icons allows Stored XSS.This issue affects Sticky Social Icons: from n/a through <= 1.2.1. | |
| Aplazada | Media (6.5) | 0.29% | — | Socialevolution WP Find Your NearestAI | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SocialEvolution WP Find Your Nearest wp-find-your-nearest allows Stored XSS.This issue affects WP Find Your Nearest: from n/a through <= 0.3.1. | |
| Analizada | Media (6.1) | 0.90% | 💥 PoC | Heateor Sassy Social Share | 30/11/2024 | 17/6/2026 | The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.69 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.4) | 0.47% | — | Codemshop Social TalkAI | 23/11/2024 | 17/6/2026 | The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's add_plus_friends and add_plus_talk shortcodes in all versions up to, and including, 1.1.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.8) | 1.2% | — | Social LoginAI | 23/11/2024 | 17/6/2026 | The Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.9.0. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such… |