Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.40% | — | Webtoffee Wordpress Backup AND MigrationAI | 17/4/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Retrieve Embedded Sensitive Data.This issue affects WordPress Backup & Migration: from n/a through <= 1.5.3. | |
| Aplazada | Alta (7.1) | 0.29% | — | Autoglot Automatic Wordpress TranslationAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Autoglot Autoglot – Automatic WordPress Translation autoglot allows Reflected XSS.This issue affects Autoglot – Automatic WordPress Translation: from n/a through <= 2.4.7. | |
| Aplazada | Media (6.5) | 0.38% | — | Wpseek Wordpress Dashboard TweeterAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in wpseek WordPress Dashboard Tweeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress Dashboard Tweeter: from n/a through 1.3.2. | |
| Aplazada | Media (5.4) | 0.51% | — | Miniorange Wordpress Rest API AuthenticationAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in miniOrange WordPress REST API Authentication wp-rest-api-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress REST API Authentication: from n/a through <= 3.6.3. | |
| Aplazada | Crítica (9.1) | 0.43% | — | Insert OR Embed Articulate Content Into WordpressAI | 10/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articulate Content into WordPress insert-or-embed-articulate-content-into-wordpress allows Upload a Web Shell to a Web Server.This issue affects Insert or Embed Articulate Content into WordPress: from n/a… | |
| Aplazada | Alta (7.1) | 0.42% | — | Ankit Singla Wordpress Spam BlockerAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ankit Singla WordPress Spam Blocker cf7-manual-spam-blocker allows Stored XSS.This issue affects WordPress Spam Blocker: from n/a through <= 2.0.5. | |
| Analizada | Media (6.3) | 0.16% | — | Felixker Wordpress/plugin Upgrade Time OUT Plugin | 9/4/2025 | 17/6/2026 | The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Aplazada | Media (5.3) | 0.82% | — | 1clickmigration 1 Click Wordpress MigrationAI | 4/4/2025 | 17/6/2026 | Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration 1-click-migration allows Retrieve Embedded Sensitive Data.This issue affects 1 Click WordPress Migration: from n/a through <= 2.5.7. | |
| Aplazada | Media (6.4) | 0.33% | — | Smart Icons FOR WordpressAI | 2/4/2025 | 17/6/2026 | The Smart Icons For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Editor-level access and above, to inject… | |
| Aplazada | Alta (7.1) | 0.39% | — | S Wordpress Galleria WP GalleriaAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in S WordPress Galleria wp-galleria allows Reflected XSS.This issue affects WordPress Galleria: from n/a through <= 1.4. | |
| Aplazada | Media (4.3) | 0.40% | — | Slimndap Theater FOR WordpressAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.18.7. | |
| Aplazada | Media (6.5) | 0.36% | — | C Johnson Footnotes FOR WordpressAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in C. Johnson Footnotes for WordPress footnotes-for-wordpress allows Stored XSS.This issue affects Footnotes for WordPress: from n/a through <= 2016.1230. | |
| Aplazada | Alta (7.1) | 0.31% | — | Pluginspoint Kento Wordpress StatsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginsPoint Kento WordPress Stats kento-wp-stats allows Stored XSS.This issue affects Kento WordPress Stats: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.14% | — | Wp-buy Wordpress Related Posts With ThumbnailsAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wp-buy wordpress related Posts with thumbnails related-posts-list-grid-and-slider-all-in-one allows Stored XSS.This issue affects wordpress related Posts with thumbnails: from n/a through <= 3.0.0.1. | |
| Aplazada | Alta (7.1) | 0.31% | — | Sureshdsk ARE YOU Robot Google Recaptcha FOR WordpressAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sureshdsk Are you robot google recaptcha for wordpress are-you-robot-recaptcha allows Reflected XSS.This issue affects Are you robot google recaptcha for wordpress: from n/a through <= 2.2. | |
| Aplazada | Media (6.5) | 0.36% | — | Chris Taylor Wordpress-mu-secure-invitesAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Taylor Secure Invites wordpress-mu-secure-invites allows Reflected XSS.This issue affects Secure Invites: from n/a through <= 1.3. | |
| Aplazada | Alta (7.1) | 0.36% | — | Zenverse Wordpress-theme-demo-barAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zenverse Theme Demo Bar wordpress-theme-demo-bar allows Reflected XSS.This issue affects Theme Demo Bar: from n/a through <= 1.6.3. | |
| Aplazada | Alta (7.2) | 0.78% | — | Wordpress ImporterAI | 26/3/2025 | 17/6/2026 | The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.8.3 via deserialization of untrusted input in the 'maybe_unserialize' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP… | |
| Aplazada | Media (6.5) | 0.72% | — | Blueglass Jobs FOR WordpressAI | 26/3/2025 | 17/6/2026 | The Jobs for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.7.11 via the 'job_postings_get_file' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server,… | |
| Analizada | Media (5.9) | 0.32% | — | Blueglass Jobs FOR Wordpress | 25/3/2025 | 17/6/2026 | The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (7.1) | 0.16% | — | Wordpress SQL BackupAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Anthony WordPress SQL Backup wordpress-sql-backup allows Stored XSS.This issue affects WordPress SQL Backup: from n/a through <= 3.5.2. | |
| Aplazada | Alta (7.1) | 0.19% | — | Donald Gilbert Wordpress Admin BAR ImprovedAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Donald Gilbert WordPress Admin Bar Improved wordpress-admin-bar-improved allows Stored XSS.This issue affects WordPress Admin Bar Improved: from n/a through <= 3.3.5. | |
| Analizada | Media (4.9) | 0.73% | — | Webtoffee Import Export Wordpress Users | 22/3/2025 | 17/6/2026 | The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the… | |
| Analizada | Media (6.5) | 0.39% | — | Webtoffee Import Export Wordpress Users | 22/3/2025 | 17/6/2026 | The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with Administrator-level access and above,… | |
| Analizada | Alta (7.2) | 0.75% | — | Webtoffee Import Export Wordpress Users | 22/3/2025 | 17/6/2026 | The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to… |