Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.28% | — | Seedprod Wordpress Notification BAR | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SeedProd WordPress Notification Bar allows Stored XSS.This issue affects WordPress Notification Bar: from n/a through 1.3.10. | |
| Aplazada | Media (5.9) | 0.28% | — | Wedevs Recaptcha Integration FOR WordpressAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs ReCaptcha Integration for WordPress wp-recaptcha-integration allows DOM-Based XSS.This issue affects ReCaptcha Integration for WordPress: from n/a through <= 1.2.7. | |
| Modificada | Media (4.3) | 0.69% | — | Iptanus Wordpress File Upload | 16/7/2024 | 17/6/2026 | The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.24.7 via the 'uploadpath' parameter of the wordpress_file_upload shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload limited files to… | |
| Aplazada | Media (6.5) | 0.51% | — | Dynamicweblab Wordpress Team ManagerAI | 12/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DynamicWebLab WordPress Team Manager allows PHP Local File Inclusion.This issue affects WordPress Team Manager: from n/a through 2.1.12. | |
| Aplazada | Media (5.3) | 0.38% | — | Patreon WordpressAI | 9/7/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in patreon Patreon WordPress patreon-connect.This issue affects Patreon WordPress: from n/a through <= 1.9.0. | |
| Aplazada | Media (5) | 0.48% | — | WordpressAI | 25/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress allows Relative Path Traversal.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, from 6.0 through… | |
| Aplazada | Media (6.5) | 0.34% | — | WordpressAI | 25/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, from 6.0 through… | |
| Aplazada | Media (6.4) | 0.47% | — | WordpressAI | 25/6/2024 | 17/6/2026 | WordPress Core is vulnerable to Stored Cross-Site Scripting via the HTML API in various versions prior to 6.5.5 due to insufficient input sanitization and output escaping on URLs. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that… | |
| Aplazada | Crítica (9.3) | 0.38% | — | Wordpress Picture Portfolio Media GalleryAI | 19/6/2024 | 17/6/2026 | The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.1 via the 'file_get_contents' function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web… | |
| Modificada | Media (5.4) | 0.36% | — | Andrewabarber Wordpress Jitsi Shortcode | 14/6/2024 | 17/6/2026 | The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.8) | 0.29% | — | Andrewabarber Wordpress Jitsi Shortcode | 14/6/2024 | 17/6/2026 | The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.3) | 0.30% | — | Awesomesupport Awesome Support Wordpress Helpdesk & Support | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5. | |
| Aplazada | Media (5.4) | 0.37% | — | Webtoffee Wordpress Backup AND MigrationAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.3. | |
| Analizada | Alta (8.8) | 0.32% | — | Pluginus Wordpress Meta Data AND Taxonomies Filter | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3. | |
| Aplazada | Media (6.5) | 0.26% | — | Praison SEO WordpressAI | 3/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mervin Praison Praison SEO WordPress seo-wordpress allows DOM-Based XSS.This issue affects Praison SEO WordPress: from n/a through <= 4.0.15. | |
| Aplazada | Media (6.4) | 0.27% | — | Miniorange Wordpress Office 365 Azure AD LoginAI | 23/5/2024 | 17/6/2026 | The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode in all versions up to, and including, 27.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.27% | — | Valvepress Wordpress Automatic PluginAI | 18/5/2024 | 17/6/2026 | The WordPress Automatic Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘autoplay’ parameter in all versions up to, and including, 3.94.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Analizada | Media (6.5) | 0.28% | — | Pluginus Wordpress Meta Data AND Taxonomies Filter | 17/5/2024 | 17/6/2026 | Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusion, Functionality Misuse.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.2. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Coderevolution Demo MY WordpressAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1. | |
| Aplazada | Baja (3.7) | 0.43% | — | Filipe Seabra Wordpress ManutencaoAI | 17/5/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Filipe Seabra WordPress Manutenção allows Functionality Bypass.This issue affects WordPress Manutenção: from n/a through 1.0.6. | |
| Aplazada | Alta (8) | 0.48% | — | Miniorange Wordpress Social Login AND RegisterAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Privilege Escalation.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.6. | |
| Aplazada | Media (4.3) | 0.22% | — | Bulk Posts Editing FOR WordpressAI | 16/5/2024 | 17/6/2026 | The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to missing or incorrect nonce validation on the plugin's AJAX actions.. This makes it possible for unauthenticated attackers to create and duplicate posts,… | |
| Aplazada | Media (4.3) | 0.30% | — | Bulk Posts Editing FOR WordpressAI | 15/5/2024 | 17/6/2026 | The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 4.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to invoke… | |
| Modificada | Media (4.8) | 0.28% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 8/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WOLF allows Stored XSS.This issue affects WOLF: from n/a through 1.0.8.2. | |
| Aplazada | Media (4.3) | 0.37% | — | Nico Martin Progressive Wordpress PWAAI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Nico Martin Progressive WordPress (PWA).This issue affects Progressive WordPress (PWA): from n/a through 2.1.13. |