Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3372 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Wordpress Plugins WP DebuggingAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.
AplazadaMedia (6.5)0.37%—Motopress Hotel Booking LiteAI2/7/20262/7/2026
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
AplazadaAlta (7.5)0.43%—Openai Chatbot FOR Wordpress HelperAI2/7/20266/10/2026
Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
AplazadaMedia (4.3)0.33%—Codexpert INC ThumbpressAI1/7/20261/7/2026
Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2.
AplazadaMedia (6.5)0.45%—Motopress Appointment BookingAI1/7/20261/7/2026
The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 2.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (6.4)0.33%—Thimpress LearnpressAI1/7/20261/7/2026
The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to, and including, 4.4.0. This is due to insufficient input sanitization and output escaping in the FilterCourseTemplate::sections() method at line 98, where the…
AplazadaAlta (7.5)0.46%—Bookingpress Appointment Booking PROAI1/7/20261/7/2026
The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is…
AplazadaMedia (6.5)0.47%—Thimpress LearnpressAI1/7/20261/7/2026
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.9.1 via the 'userId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated…
AnalizadaCrítica (9.1)0.52%—Fastify/express30/6/20261/7/2026
@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of paths and regular expressions) are left unprefixed inside prefixed plugin scopes, so middleware registered with those forms does not match the…
AplazadaAlta (8.5)0.36%—Motopress Restaurant MenuAI26/6/202626/6/2026
Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.
AplazadaMedia (4.3)0.25%—Seopress PROAI26/6/202626/6/2026
Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.
AplazadaAlta (7.1)0.25%—Valvepress AutomaticAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.
AplazadaCrítica (9.3)0.40%—Simple PAY WordpressAI26/6/202626/6/2026
Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.
AplazadaAlta (7.1)0.25%💥 PoCMappress MapsAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.
AplazadaMedia (4.3)0.25%—Motopress Restaurant MenuAI26/6/20265/10/2026
Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.
AplazadaAlta (8.5)0.15%—Expressupdate AgentAI26/6/202626/6/2026
An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.
AplazadaAlta (7.1)0.25%—TablepressAI25/6/202629/6/2026
Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.
AnalizadaMedia (4.3)0.29%—Rapid7 Insightconnect Compression25/6/202629/6/2026
Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content cannot be controlled by the attacker.
AplazadaAlta (8.4)0.42%—FlatpressAI23/6/202625/6/2026
FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in Smarty templates. Attackers can inject arbitrary HTML and JavaScript through these fields to execute malicious scripts in browsers of viewers…
AplazadaAlta (8.8)0.43%—Wp-feedstats Wordpress PluginAI23/6/202623/6/2026
The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above.
AplazadaAlta (8.7)0.63%—Wordpress Time CapsuleAI20/6/202629/9/2026
WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies and access the…
AplazadaMedia (6.5)0.34%—Thimpress WP Hotel BookingAI19/6/202622/6/2026
The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' booking line items, enumerate active coupons, and read pricing data.
AplazadaMedia (6.4)0.34%—Addonspress Advanced ImportAI19/6/202622/6/2026
The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the plugin using wp_remote_get() to fetch a user-supplied URL without validating that the URL does not point to internal or private network resources in the…
AplazadaMedia (6.4)0.20%—Blubrry PowerpressAI18/6/202618/6/2026
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all versions up to, and including, 11.16.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level…
AplazadaMedia (4.3)0.25%—Pressprimer QuizAI18/6/202618/6/2026
The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.0 via the 'rule_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated…