Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.27% | — | Wpmarka Wordpress Auction PluginAI | 6/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Marka WordPress Auction Plugin wp-auctions allows Stored XSS.This issue affects WordPress Auction Plugin: from n/a through <= 3.7. | |
| Aplazada | Crítica (9.3) | 0.46% | — | Wpmarka Wordpress Auction PluginAI | 6/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Marka WordPress Auction Plugin wp-auctions allows SQL Injection.This issue affects WordPress Auction Plugin: from n/a through <= 3.7. | |
| Aplazada | Media (5.9) | 0.30% | — | Portfoliohub Wordpress Portfolio BuilderAI | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in portfoliohub WordPress Portfolio Builder – Portfolio Gallery uber-grid allows Stored XSS.This issue affects WordPress Portfolio Builder – Portfolio Gallery: from n/a through <= 1.1.7. | |
| Analizada | Media (4.3) | 0.22% | — | Cimatti Wordpress Contact Forms | 27/11/2024 | 17/6/2026 | The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to delete forms via a… | |
| Aplazada | Media (6.4) | 0.40% | — | Support SVG Upload SVG Files IN Wordpress Without HassleAI | 26/11/2024 | 17/6/2026 | The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Crítica (9.8) | 1.2% | — | Mojoomla Wordpress GYM Management System | 23/11/2024 | 17/6/2026 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on… | |
| Analizada | Alta (8.8) | 0.60% | — | Mojoomla Wordpress GYM Management System | 23/11/2024 | 17/6/2026 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Aplazada | Media (6.1) | 0.46% | — | Wordpress Brute Force ProtectionAI | 23/11/2024 | 17/6/2026 | The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.6. This makes it possible for unauthenticated… | |
| Analizada | Media (6.6) | 0.75% | — | Geomywp GEO MY WordpressGeomywp GEO MY Wordpress Premium Settings | 22/11/2024 | 17/6/2026 | The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server. | |
| Analizada | Media (6.1) | 0.60% | — | Slimndap Theater FOR Wordpress | 21/11/2024 | 17/6/2026 | The Theater for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 0.18.6.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Crítica (9.1) | 0.45% | — | Welaunch Wordpress Gdpr | 19/11/2024 | 17/6/2026 | The WordPress GDPR plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'WordPress_GDPR_Data_Delete::check_action' function in all versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to delete arbitrary users. | |
| Analizada | Media (6.1) | 0.31% | — | Welaunch Wordpress Gdpr | 19/11/2024 | 17/6/2026 | The WordPress GDPR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_firstname' and 'gdpr_lastname' parameters in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Crítica (9.8) | 0.46% | — | Pressaholic Wordpress Video Robot | 18/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pressaholic WordPress Video Robot - The Ultimate Video Importer allows SQL Injection.This issue affects WordPress Video Robot - The Ultimate Video Importer: from n/a through 1.20.0. | |
| Aplazada | Crítica (9.9) | 0.49% | — | Pushassist Push Notifications FOR WordpressAI | 16/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in pushassist Push Notifications for WordPress by PushAssist push-notification-for-wp-by-pushassist allows Upload a Web Shell to a Web Server.This issue affects Push Notifications for WordPress by PushAssist: from n/a through <= 3.0.8. | |
| Aplazada | Alta (7.2) | 0.51% | — | Login Using Wordpress Users WP AS Saml IDPAI | 16/11/2024 | 17/6/2026 | The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.15.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Alta (8.8) | 0.58% | — | Pressaholic Wordpress Video RobotAI | 16/11/2024 | 17/6/2026 | The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due to insufficient validation on user meta that can be updated in the wpvr_rate_request_result() function in all versions up to, and including, 1.20.0. This makes it possible for authenticated attackers,… | |
| Analizada | Media (5.9) | 0.36% | — | Blueglass Jobs FOR Wordpress | 15/11/2024 | 17/6/2026 | The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.62% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 14/11/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-editor allows Path Traversal.This issue affects WOLF: from n/a through <= 1.0.8.3. | |
| Aplazada | Alta (7.1) | 0.29% | — | BEN Moody Srcset Responsive Images FOR WordpressAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ben.moody SrcSet Responsive Images for WordPress truenorth-srcset allows Reflected XSS.This issue affects SrcSet Responsive Images for WordPress: from n/a through <= 1.4. | |
| Aplazada | Crítica (9.8) | 0.85% | — | Wordpress User Extra FieldsAI | 9/11/2024 | 17/6/2026 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_manage_file_chunk_upload() function in all versions up to, and including, 16.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected… | |
| Analizada | Crítica (9.8) | 35% | 💥 PoC | Vibethemes Wordpress Learning Management System | 9/11/2024 | 17/6/2026 | The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for… | |
| Analizada | Baja (3.5) | 0.25% | — | Iptanus Wordpress File Upload | 1/11/2024 | 17/6/2026 | Broken Access Control vulnerability in Nickolas Bossinas WordPress File Upload allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress File Upload: from n/a through 4.24.7. | |
| Aplazada | Media (5.3) | 0.42% | — | Language Translate Widget FOR Wordpress ConveyethisAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in ConveyThis Translate Team Language Translate Widget for WordPress – ConveyThis allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Language Translate Widget for WordPress – ConveyThis: from n/a through 234. | |
| Aplazada | Media (5.3) | 0.42% | — | Kanbanwp Kanban Boards FOR WordpressAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Kanban for WordPress Kanban Boards for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21. | |
| Aplazada | Media (6.4) | 0.34% | — | WP Team Wordpress Team Member PluginAI | 30/10/2024 | 17/6/2026 | The WP Team – WordPress Team Member Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's htteamember shortcode in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… |