Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.30% | — | Elex Wordpress Helpdesk Customer Ticketing SystemAI | 5/2/2026 | 17/6/2026 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.5. This is due to missing capability checks on the eh_crm_ticket_general function combined with a shared nonce that is exposed to low-privileged users. This… | |
| Aplazada | Media (4.3) | 0.14% | — | Surveyjs Drag Drop Wordpress Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the `SurveyJS_CloneSurvey` AJAX action. This… | |
| Aplazada | Media (4.3) | 0.15% | — | Surveyjs Drag Drop Wordpress Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce verification on the 'SurveyJS_RenameSurvey' AJAX action. This makes it… | |
| Aplazada | Media (4.3) | 0.18% | — | Trusona FOR WordpressAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Trusona Trusona for WordPress trusona allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trusona for WordPress: from n/a through <= 2.0.0. | |
| Analizada | Alta (7.4) | 0.60% | — | Microsoft 365 Word Copilot | 22/1/2026 | 17/6/2026 | Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Alta (8.8) | 0.47% | — | Webpros Wordpress ToolkitAI | 22/1/2026 | 17/6/2026 | An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation. | |
| Aplazada | Media (5.4) | 0.12% | — | Mikado-themes Pawfriends - PET Shop AND Veterinary Wordpress ThemeAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Cross Site Request Forgery.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through <= 1.3. | |
| Aplazada | Media (4.3) | 0.15% | — | Aa-team Wordpress Movies Bulk ImporterAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AA-Team Wordpress Movies Bulk Importer movies importer allows Cross Site Request Forgery.This issue affects Wordpress Movies Bulk Importer: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.30% | — | Adamlabs Wordpress Photo GalleryAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamlabs WordPress Photo Gallery photo-gallery-portfolio allows Reflected XSS.This issue affects WordPress Photo Gallery: from n/a through <= 1.1.0. | |
| Aplazada | Media (5) | 0.27% | — | DK PDF Wordpress PDF GeneratorAI | 16/1/2026 | 17/6/2026 | The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3.0 via the 'addContentToMpdf' function. This makes it possible for authenticated attackers, author level and above, to make web requests to arbitrary locations originating… | |
| Aplazada | Media (4.3) | 0.12% | — | Stopwords FOR CommentsAI | 14/1/2026 | 17/6/2026 | The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing nonce validation on the 'set_stopwords_for_comments' and 'delete_stopwords_for_comments' functions. This makes it possible for unauthenticated attackers to add… | |
| Analizada | Alta (7.8) | 0.61% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 13/1/2026 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Aplazada | Alta (8.4) | 0.36% | — | Lemonsoft Wordpress ADD ONAI | 13/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lemonsoft WordPress add on allows Cross-Site Scripting (XSS).This issue affects WordPress add on: 2025.7.1. | |
| Analizada | Alta (8.1) | 0.80% | — | Zohocorp Manageengine Pam360Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Password Manager PRO | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality. | |
| Aplazada | Media (5.4) | 0.20% | — | Passionatebrains Ga4wp Google Analytics FOR WordpressAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GA4WP: Google Analytics for WordPress: from n/a through <= 2.10.0. | |
| Aplazada | Media (5.4) | 0.20% | — | Niklaslindemann Bulk Landing Page Creator FOR Wordpress LpageryAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in niklaslindemann Bulk Landing Page Creator for WordPress LPagery lpagery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Landing Page Creator for WordPress LPagery: from n/a through <= 2.4.9. | |
| Aplazada | Media (4.3) | 0.22% | — | Campaignmonitor Campaign Monitor FOR WordpressAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Campaign Monitor for WordPress: from n/a through 2.9.1. | |
| Aplazada | Media (6.5) | 0.15% | — | Jcaruso001 Flaming-password-resetAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jcaruso001 Flaming Password Reset flaming-password-reset allows Stored XSS.This issue affects Flaming Password Reset: from n/a through <= 1.0.3. | |
| Aplazada | Alta (8.8) | 0.30% | — | Aa-team Premium AGE Verification / Restriction FOR WordpressAIAa-team Responsive Coming Soon Landing Page / Holding Page FOR WordpressAI | 6/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive… | |
| Aplazada | Media (4.3) | 0.18% | — | Theatre FOR WordpressAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.19. | |
| Aplazada | Crítica (9.8) | 0.43% | 💥 PoC | FS Registration PasswordAI | 6/1/2026 | 7/10/2026 | The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change… | |
| Aplazada | Crítica (9.8) | 0.37% | — | AS Password Field IN Default Registration FormAI | 6/1/2026 | 7/10/2026 | The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for… | |
| Aplazada | Alta (8.6) | 1.7% | 💥 Exploit | Team Wordpress PluginAI | 5/1/2026 | 17/6/2026 | The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Aplazada | Alta (8.5) | 0.24% | — | Codedraft Mediabay - Wordpress Media Library FoldersAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Folders allows Blind SQL Injection.This issue affects Mediabay - WordPress Media Library Folders: from n/a through 1.4. | |
| Aplazada | Media (4.3) | 0.27% | — | Boomdevs Wordpress Coming SoonAI | 31/12/2025 | 28/9/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Messiah BoomDevs WordPress Coming Soon coming-soon-by-boomdevs allows Retrieve Embedded Sensitive Data.This issue affects BoomDevs WordPress Coming Soon: from n/a through <= 1.0.4. |