Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.29% | — | Booking Plugin FOR Wordpress Appointments Time SlotAI | 19/11/2025 | 17/6/2026 | The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 due to missing validation on the tslot_appt_email AJAX action. This makes it possible for unauthenticated attackers to send appointment notification emails… | |
| Aplazada | Media (5.3) | 0.20% | — | Slimndap Theater FOR WordpressAI | 13/11/2025 | 7/10/2026 | Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.18.8. | |
| Aplazada | Media (6.4) | 0.22% | — | Wordpress Content FlipperAI | 13/11/2025 | 7/10/2026 | The WordPress Content Flipper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bgcolor' shortcode attribute of the 'flipper_front' shortcode in all versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (7.2) | 0.52% | — | Wordpress LMS Academy LMSAI | 8/11/2025 | 7/10/2026 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.8 via deserialization of untrusted input in the 'import_all_courses' function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.4) | 0.19% | — | Html Forms Simple Wordpress Forms PluginAI | 8/11/2025 | 7/10/2026 | The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Alta (8.1) | 0.44% | — | Blanka Theme Developers Blanka - ONE Page Wordpress ThemeAI | 6/11/2025 | 7/10/2026 | Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File Inclusion.This issue affects Blanka - One Page WordPress Theme: from n/a through < 1.5. | |
| Aplazada | Media (5.4) | 0.13% | — | Social Media Wpcf7 Stop WordsAI | 4/11/2025 | 17/6/2026 | The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the smWpCfSwOptions() function. This makes it possible for unauthenticated attackers to update the plugin's settings… | |
| Aplazada | Media (6.5) | 0.17% | — | Wordpress GutenbergAI | 31/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gutenberg gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through <= 21.8.2. | |
| Aplazada | Alta (8.8) | 0.70% | — | Wordpress User Extra FieldsAI | 31/10/2025 | 7/10/2026 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in all versions up to, and including, 16.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… | |
| Aplazada | Media (6.5) | 0.17% | — | Builderall Builder FOR WordpressAI | 27/10/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Stored XSS.This issue affects Builderall Builder for WordPress: from n/a through <= 3.0.1. | |
| Aplazada | Baja (3.7) | 0.31% | — | Wpexperts Password ProtectedAI | 25/10/2025 | 17/6/2026 | The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and similar headers) to determine user IP addresses in the… | |
| Aplazada | Media (4.3) | 0.20% | — | Miniorange Password Policy ManagerAI | 25/10/2025 | 30/9/2026 | The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'moppm_ajax' AJAX endpoint in all versions up to, and including, 2.0.5. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (5.4) | 0.27% | — | Microsoft Azure Storage FOR WordpressAI | 24/10/2025 | 17/6/2026 | The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in all versions up to, and including, 4.5.1. This is due to missing capability checks on the 'azure-storage-media-replace' AJAX action. This makes it possible for authenticated attackers with… | |
| Aplazada | Media (6.3) | 0.27% | — | URL Shortener Plugin FOR WordpressAI | 24/10/2025 | 17/6/2026 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provided by the API due to a missing capability check on the verifyRequest function in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (7.1) | 0.24% | — | Themewarriors Whatsapp Chat FOR Wordpress AND WoocommerceAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeWarriors WhatsApp Chat for WordPress and WooCommerce tw-whatsapp-chat-rotator allows Reflected XSS.This issue affects WhatsApp Chat for WordPress and WooCommerce: from n/a through <= 1.2.1. | |
| Modificada | Alta (7.1) | 0.25% | — | Vibethemes Wordpress Learning Management System | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes WPLMS wplms_plugin allows Reflected XSS.This issue affects WPLMS: from n/a through <= 1.9.9.8. | |
| Modificada | Alta (7.5) | 0.36% | — | Vibethemes Wordpress Learning Management System | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1.9.9.7. | |
| Aplazada | Alta (7.1) | 0.30% | — | Calvaweb Password Only LoginAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Calvaweb Password only login password-only-login allows Reflected XSS.This issue affects Password only login: from n/a through <= 0.2. | |
| Aplazada | Crítica (9.8) | 0.79% | 💥 PoC | Ownid Passwordless LoginAI | 15/10/2025 | 17/6/2026 | The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to… | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7) | 0.39% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Aplazada | Media (6.4) | 0.19% | — | Wordpress Live Webcam Widget ShortcodeAI | 11/10/2025 | 17/6/2026 | The WordPress Live Webcam Widget & Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Crítica (9.3) | 0.57% | — | Microsoft 365 Word Copilot | 9/10/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Alta (7.7) | 0.27% | — | Find ME ON WordpressAI | 8/10/2025 | 17/6/2026 | The Find Me On WordPress plugin through 2.0.9.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers and above to perform SQL injection attacks | |
| Aplazada | Alta (8.1) | 0.70% | — | BEI FEN Wordpress Backup PluginAI | 30/9/2025 | 17/6/2026 | The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the 'task'. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing… |