Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.40% | — | Content NO CacheAI | 24/12/2024 | 17/6/2026 | The Content No Cache: prevent specific content from being cached plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 0.1.2 via the eos_dyn_get_content action due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.44% | — | Codetides Advanced Floating ContentAI | 24/12/2024 | 17/6/2026 | The Advanced Floating Content plugin for WordPress is vulnerable to SQL Injection via the 'floating_content_duplicate_post' function in all versions up to, and including, 3.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Analizada | Media (5.3) | 0.48% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 18/12/2024 | 17/6/2026 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.4 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract… | |
| Aplazada | Media (4.3) | 0.31% | — | GET Post Content ShortcodeAI | 14/12/2024 | 17/6/2026 | The Get Post Content Shortcode plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.4 via the 'post-content' shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Alta (7.1) | 0.35% | — | Metup Clevernode Related ContentAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metup CleverNode Related Content clevernode-related-content allows Reflected XSS.This issue affects CleverNode Related Content: from n/a through <= 1.1.5. | |
| Aplazada | Media (4.3) | 0.23% | — | Basar Ventures Autowp AI Content Writer RewriterAI | 13/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Basar Ventures AutoWP autowp-ai-content-writer-rewriter allows Cross Site Request Forgery.This issue affects AutoWP: from n/a through <= 2.0.8. | |
| Analizada | Media (4.8) | 0.37% | — | Theluckywp Luckywp Table OF Contents | 12/12/2024 | 17/6/2026 | The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.1) | 0.41% | — | Magger AI Content WriterAI | 12/12/2024 | 17/6/2026 | The AI Content Writer, RSS Feed to Post, Autoblogging SEO Help plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 6.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.4) | 0.57% | — | Magazine3 Easy Table OF ContentsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Magazine3 Easy Table of Contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Table of Contents: from n/a through 2.0.45.2. | |
| Aplazada | Media (5.3) | 0.57% | — | Fantasticplugins Fantastic Content Protector FreeAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fantastic Plugins Fantastic Content Protector Free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fantastic Content Protector Free: from n/a through 2.6. | |
| Aplazada | Media (5.3) | 0.45% | — | Wpexpertdeveloper WP Private Content PlusAI | 6/12/2024 | 17/6/2026 | The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.1 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles… | |
| Aplazada | Alta (7.1) | 0.17% | — | Oliver Lindner Protect Your ContentAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Oliver Lindner Protect Your Content protect-your-content allows Stored XSS.This issue affects Protect Your Content: from n/a through <= 1.0.2. | |
| Aplazada | Media (5.3) | 0.42% | — | Ideinteractive Content Audit ExporterAI | 30/11/2024 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ideinteractive Content Audit Exporter content-audit-exporter allows Retrieve Embedded Sensitive Data.This issue affects Content Audit Exporter: from n/a through <= 1.1. | |
| Aplazada | Media (5.1) | 0.46% | — | Opentext Secure Content ManagerAI | 22/11/2024 | 17/6/2026 | : Insufficient Logging vulnerability in OpenText Secure Content Manager on Windows allows Audit Log Manipulation.This issue affects Secure Content Manager: from 10.1 before <24.4. End-users can potentially exploit the vulnerability to exclude audit trails from being recorded on the client side. | |
| Analizada | Media (5.3) | 0.57% | — | Cayenne Anonymous Restricted Content | 21/11/2024 | 17/6/2026 | The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to logged-in users. | |
| Analizada | Media (4.8) | 0.21% | — | Cminds CM Table OF Contents | 21/11/2024 | 17/6/2026 | The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Aplazada | Media (4.3) | 0.47% | — | If-so IF SO Dynamic Content PersonalizationAI | 21/11/2024 | 17/6/2026 | The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.2.1 via the 'ifso-show-post' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.6) | 0.80% | 💥 PoC | Gunghoinc Exclusive Content Password ProtectAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gunghoinc Exclusive Content Password Protect exclusive-content-password-protect allows Upload a Web Shell to a Web Server.This issue affects Exclusive Content Password Protect: from n/a through <= 1.1.0. | |
| Analizada | Baja (3.8) | 0.20% | — | Cminds CM Table OF Contents | 18/11/2024 | 17/6/2026 | The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack | |
| Modificada | Media (4.8) | 0.28% | — | Target-info Mycurator Content Curation | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mtilly MyCurator Content Curation mycurator allows Stored XSS.This issue affects MyCurator Content Curation: from n/a through <= 3.78. | |
| Aplazada | Alta (7.1) | 0.29% | — | Ben.moody Content-syndication-toolkit-readerAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ben.moody Content Syndication Toolkit Reader content-syndication-toolkit-reader allows Reflected XSS.This issue affects Content Syndication Toolkit Reader: from n/a through <= 1.5. | |
| Aplazada | Alta (7.1) | 0.27% | — | Perception System System PVT LTD Ajax Content FilterAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Perception System System Pvt. Ltd. Ajax Content Filter ajax-content-filter allows Reflected XSS.This issue affects Ajax Content Filter: from n/a through <= 1.0. | |
| Analizada | Alta (7.3) | 0.46% | — | Cozmoslabs Membership & Content Restriction - Paid Member Subscriptions | 9/11/2024 | 17/6/2026 | The The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.13.0. This is due to the software allowing users to execute an action that does not properly validate a… | |
| Aplazada | Media (4.3) | 0.31% | — | Content Slider BlockAI | 9/11/2024 | 17/6/2026 | The Content Slider Block plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.1.5 via the [csb] shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Media (4.8) | 0.37% | — | Dublue Table OF Contents Plus | 5/11/2024 | 17/6/2026 | The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed |