Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.6) | 0.41% | — | Webtoffee Import Export Wordpress Users | 22/3/2025 | 17/6/2026 | The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary… | |
| Analizada | Alta (7.1) | 0.29% | — | Erwinwolff Wordpress Activity-o-meter | 7/3/2025 | 17/6/2026 | The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins. | |
| Aplazada | Alta (8.8) | 0.46% | — | Wordpress Awesome Import Export Awesome Import ExportAI | 5/3/2025 | 17/6/2026 | The WordPress Awesome Import & Export Plugin - Import & Export WordPress Data plugin for WordPress is vulnerable arbitrary SQL Execution and privilege escalation due to a missing capability check on the renderImport() function in all versions up to, and including, 4.1.1. This makes it possible for authenticated… | |
| Aplazada | Alta (7.2) | 0.70% | — | Beaver Builder Wordpress AssistantAI | 3/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Beaver Builder WordPress Assistant assistant allows Object Injection.This issue affects WordPress Assistant: from n/a through <= 1.5.1. | |
| Aplazada | Alta (8.8) | 0.77% | — | Surveyjs Drag AND Drop Wordpress Form BuilderAI | 1/3/2025 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to arbitrary file deletion due to a missing capability check on the callback function of the SurveyJS_DeleteFile class in all versions up to, and including, 1.12.17. This… | |
| Aplazada | Media (6.5) | 0.28% | — | Webandprint AR FOR WordpressAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webandprint AR For WordPress ar-for-wordpress allows DOM-Based XSS.This issue affects AR For WordPress: from n/a through <= 7.7. | |
| Analizada | Media (4.3) | 0.17% | — | Iptanus Wordpress File Upload | 25/2/2025 | 17/6/2026 | The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.25.2. This is due to missing or incorrect nonce validation on the 'wfu_file_details' function. This makes it possible for unauthenticated attackers to modify user data details associated… | |
| Aplazada | Media (6.5) | 0.27% | — | Aaron D. Campbell Google-maps-for-wordpressAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aaron D. Campbell Google Maps for WordPress google-maps-for-wordpress allows DOM-Based XSS.This issue affects Google Maps for WordPress: from n/a through <= 1.0.3. | |
| Aplazada | Media (6.5) | 0.23% | — | Upcasted AWS S3 FOR Wordpress PluginAI | 16/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in upcasted AWS S3 for WordPress Plugin – Upcasted upcasted-s3-offload allows Stored XSS.This issue affects AWS S3 for WordPress Plugin – Upcasted: from n/a through <= 3.0.3. | |
| Aplazada | Alta (7.1) | 0.31% | — | Rusalex Wordpress-to-candidate FOR Salesforce CRMAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RusAlex WordPress-to-candidate for Salesforce CRM salesforce-wordpress-to-candidate allows Reflected XSS.This issue affects WordPress-to-candidate for Salesforce CRM: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.1) | 0.28% | — | Cantonbolo Wordpress TaobaokeAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CantonBolo WordPress 淘宝客插件 taobaoke allows Reflected XSS.This issue affects WordPress 淘宝客插件: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.1) | 0.28% | — | Arash Safari Qmean Wordpress DID YOU MeanAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arash Safari QMean – WordPress Did You Mean qmean allows Reflected XSS.This issue affects QMean – WordPress Did You Mean: from n/a through <= 2.0. | |
| Modificada | Alta (7.2) | 0.68% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 3/2/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through <= 1.0.8.5. | |
| Aplazada | Alta (7.1) | 0.33% | — | Abinav Thakuri Wordpress SignatureAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abinav Thakuri WordPress Signature wordpress-signature allows Reflected XSS.This issue affects WordPress Signature: from n/a through <= 0.1. | |
| Analizada | Media (5.4) | 0.71% | 💥 Exploit | Megamindstechnologies Wordpress Email Newsletter | 1/2/2025 | 17/6/2026 | The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (5.3) | 0.39% | — | Cimatti Wordpress Contact Forms | 1/2/2025 | 17/6/2026 | The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to download other user… | |
| Analizada | Media (6.5) | 0.35% | — | Modalsurvey Wordpress Survey AND Poll | 30/1/2025 | 17/6/2026 | The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'survey' shortcode in all versions up to, and including, 1.7.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Media (5.9) | 0.35% | — | Themeisle AI Chatbot FOR Wordpress Hyve LiteAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Stored XSS.This issue affects AI Chatbot for WordPress – Hyve Lite: from n/a through <= 1.2.2. | |
| Aplazada | Media (6.5) | 0.52% | — | Patreon WordpressAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in patreon Patreon WordPress patreon-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Patreon WordPress: from n/a through <= 1.9.1. | |
| Analizada | Media (6.1) | 0.26% | — | Suhas93 SEO Blogger TO Wordpress 301 Redirector | 23/1/2025 | 17/6/2026 | The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions up to, and including, 0.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.1) | 0.30% | — | Markcoker Wordpress File SearchAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in markcoker WordPress File Search wpfilesearch allows Reflected XSS.This issue affects WordPress File Search: from n/a through <= 1.2. | |
| Aplazada | Alta (7.1) | 0.38% | — | Martin Ziegert Real Wordpress SidebarAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in martin_ziegert REAL WordPress Sidebar drag-and-drop-custom-sidebar allows Stored XSS.This issue affects REAL WordPress Sidebar: from n/a through <= 0.1. | |
| Aplazada | Alta (7.1) | 0.39% | — | Osolwordpress Customizable-captcha-and-contact-us-formAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osolwordpress Customizable Captcha and Contact Us customizable-captcha-and-contact-us-form allows Reflected XSS.This issue affects Customizable Captcha and Contact Us: from n/a through <= 1.0.2. | |
| Aplazada | Alta (8.5) | 0.37% | — | Notfound Hero Mega Menu - Responsive Wordpress MenuAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows SQL Injection. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5. | |
| Aplazada | Media (5.5) | 0.34% | — | Import ANY XML OR CSV File TO Wordpress PROAI | 19/1/2025 | 17/6/2026 | The Import any XML or CSV File to WordPress PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level… |