Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2442 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.23% | — | Call TO Action PluginAI | 22/4/2026 | 17/6/2026 | The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.3. This is due to missing nonce validation in the cbox_options_page() function which handles saving, creating, and deleting plugin settings. The form rendered on the settings page does… | |
| Aplazada | Media (5.5) | 0.24% | — | E-plugins Real Estate PROAI | 22/4/2026 | 17/6/2026 | The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Crítica (9.8) | 0.65% | — | EssentialpluginAI | 17/4/2026 | 17/6/2026 | All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and… | |
| Aplazada | Alta (7.2) | 0.32% | — | Plugin-planet PrismaticAI | 16/4/2026 | 17/6/2026 | The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, and including, 3.7.3. This is due to insufficient input sanitization and output escaping on user-supplied attributes within the 'prismatic_decode' function. This makes it… | |
| Aplazada | Media (6.4) | 0.27% | — | Weplugins WP MapsAI | 16/4/2026 | 7/10/2026 | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'put_wpgm' shortcode in all versions up to, and including, 4.8.7. This is due to insufficient input sanitization and output escaping on user-supplied… | |
| Aplazada | Media (4.3) | 0.10% | — | Userproplugin UserproAI | 15/4/2026 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro userpro allows Cross Site Request Forgery.This issue affects Userpro: from n/a through < 5.1.11. | |
| Aplazada | Media (4.3) | 0.23% | — | Bplugins 3D Viewer Embed 3D ModelsAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer – Embed 3D Models: from n/a through <= 1.8.5. | |
| Aplazada | Alta (7.2) | 0.69% | — | Shapedplugin Smart Post ShowAI | 14/4/2026 | 17/6/2026 | The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.5) | 0.50% | — | Nocobase Plugin-workflow-javascriptAI | 13/4/2026 | 17/6/2026 | A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/plugin-workflow-javascript/src/server/Vm.js. Performing a manipulation results in sandbox issue. The attack can be initiated remotely. The… | |
| Analizada | Media (6.9) | 0.28% | — | Ajenti Plugin Core | 10/4/2026 | 17/6/2026 | ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication. This vulnerability is fixed in 0.112. | |
| Analizada | Crítica (9.3) | 0.45% | — | Ajenti Plugin Core | 10/4/2026 | 17/6/2026 | ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the password authentication This vulnerability is fixed in 0.112. | |
| Aplazada | Media (6.1) | 0.35% | — | Royal Wordpress Backup Restore PluginAI | 10/4/2026 | 17/6/2026 | The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpr_pending_template' parameter in all versions up to, and including, 1.0.16 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Pendiente de análisis | Media (5.4) | 0.20% | — | Deepin Dde-control-centerAIPlugin-deepinidAI | 9/4/2026 | 17/6/2026 | dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the deepinid cloud service. Prior to 6.1.80, plugin-deepinid is configured to skip TLS certificate verification when fetching the user's avatar from openapi.deepin.com or… | |
| Aplazada | Media (5.3) | 0.45% | — | Booking-wp-plugin BooklyAI | 9/4/2026 | 17/6/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it… | |
| Aplazada | Media (4.3) | 0.16% | — | Pluginus Bear Bulk Editor AND Products Manager ProfessionalAI | 8/4/2026 | 24/7/2026 | The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe_delete_tax_term() function. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.18% | — | Pluginus BearAI | 8/4/2026 | 24/7/2026 | The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe_redraw_table_row() function. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.26% | — | Prowcplugins Product Price BY Formula FOR WoocommerceAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in ProWCPlugins Product Price by Formula for WooCommerce product-price-by-formula-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Price by Formula for WooCommerce: from n/a through <= 2.5.6. | |
| Aplazada | Media (5.3) | 0.29% | — | Paymentplugins Payment Plugins FOR Paypal WoocommerceAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Payment Plugins Payment Plugins for PayPal WooCommerce pymntpl-paypal-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Plugins for PayPal WooCommerce: from n/a through <= 2.0.13. | |
| Aplazada | Media (4.7) | 0.28% | — | Wpplugins Hide MY WP GhostAI | 8/4/2026 | 24/7/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows Phishing.This issue affects Hide My WP Ghost: from n/a through < 7.0.00. | |
| Aplazada | Alta (7.2) | 0.51% | — | Plugin-planet Blackhole FOR BAD BotsAI | 26/3/2026 | 17/6/2026 | The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and including 3.8. This is due to insufficient input sanitization and output escaping. The plugin uses sanitize_text_field() when capturing bot data (which strips HTML tags… | |
| Aplazada | Media (6.4) | 0.42% | — | Plugin-planet Simple Download CounterAI | 26/3/2026 | 17/6/2026 | The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortcode in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes, specifically the 'text' and 'cat' attributes.… | |
| Aplazada | Alta (7.1) | 0.25% | — | Booking-wp-plugin BooklyAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bookly Bookly bookly-responsive-appointment-booking-tool allows Reflected XSS.This issue affects Bookly: from n/a through <= 26.7. | |
| Aplazada | Media (5.3) | 0.32% | — | Pickplugins User VerificationAI | 25/3/2026 | 17/6/2026 | Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This issue affects User Verification: from n/a through <= 2.0.45. | |
| Aplazada | Media (6.5) | 0.33% | — | Bplugins B BlocksAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in bPlugins B Blocks b-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B Blocks: from n/a through < 2.0.30. | |
| Aplazada | Media (6.5) | 0.34% | — | Pickplugins Product Slider FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Slider for WooCommerce: from n/a through <= 1.13.61. |