Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

430 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.47%—Accordion Shortcodes Project Accordion Shortcodes30/1/202317/6/2026
The Accordion Shortcodes WordPress plugin through 2.4.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
ModificadaMedia (5.4)0.39%—Youtube Shortcode Project Youtube Shortcode23/1/202317/6/2026
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Youtube shortcode <= 1.8.5 versions.
ModificadaMedia (5.4)0.47%—Easy Bootstrap Shortcode Project Easy Bootstrap Shortcode23/1/202317/6/2026
The Easy Bootstrap Shortcode WordPress plugin through 4.5.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users…
ModificadaMedia (5.4)0.47%—Codelights-shortcodes-and-widgets Project Codelights-shortcodes-and-widgets16/1/202317/6/2026
The Sidebar Widgets by CodeLights WordPress plugin through 1.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege…
ModificadaMedia (4.8)0.56%—Codelights-shortcodes-and-widgets Project Codelights-shortcodes-and-widgets20/12/202217/6/2026
The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Extra CSS class’ parameter in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
ModificadaAlta (8.8)0.76%—Averta Shortcodes AND Extra Features FOR Phlox Theme12/12/202217/6/2026
The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
ModificadaAlta (8.8)0.33%—Getshortcodes Shortcodes Ultimate8/11/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress.
ModificadaMedia (4.3)0.32%—Getshortcodes Shortcodes Ultimate11/10/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Shortcodes Ultimate plugin <= 5.12.0 at WordPress leading to plugin preset settings change.
ModificadaMedia (4.8)0.58%—Wpchill CPO Shortcodes23/9/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CPO Shortcodes plugin <= 1.5.0 at WordPress.
ModificadaMedia (4.8)0.68%—ADD Shortcodes Actions AND Filters Project ADD Shortcodes Actions AND Filters23/9/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability Add Shortcodes Actions And Filters plugin <= 2.0.9 at WordPress.
ModificadaAlta (7.2)1.2%—Oxilab Shortcode Addons27/7/202217/6/2026
Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress.
ModificadaMedia (5.3)3.3%—Oxilab Shortcode Addons21/7/202217/6/2026
Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.
ModificadaMedia (6.1)1.4%—Averta Shortcodes AND Extra Features FOR Phlox Theme11/7/202217/6/2026
The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)0.80%—Custom Tinymce Shortcode Button Project Custom Tinymce Shortcode Button16/5/202217/6/2026
The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting.
ModificadaMedia (5.4)0.60%—Custom Content Shortcode Project Custom Content Shortcode7/3/202217/6/2026
The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. Please note that such attack is still possible by…
ModificadaMedia (4.3)0.44%—Custom Content Shortcode Project Custom Content Shortcode7/3/202217/6/2026
The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to display arbitrary files from the filesystem (such as logs, .htaccess etc), as well as perform Local File Inclusion attacks as PHP…
ModificadaMedia (4.3)0.79%—Custom Content Shortcode Project Custom Content Shortcode7/3/202217/6/2026
The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of…
ModificadaMedia (4.3)0.81%—User Meta Shortcodes Project User Meta Shortcodes13/12/202117/6/2026
The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes
ModificadaMedia (4.3)0.81%—Page/post Content Shortcode Project Page/post Content Shortcode13/12/202117/6/2026
The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors.
ModificadaMedia (5.4)0.62%—Getshortcodes Shortcodes Ultimate20/9/202117/6/2026
The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like…
ModificadaMedia (6.1)3.9%—Visualshortcodes Ninja27/12/201917/6/2026
Cross-site scripting (XSS) vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the shortcode parameter.
ModificadaMedia (6.5)0.87%—Olevmedia Shortcodes26/9/201917/6/2026
The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.
ModificadaCrítica (9.8)2.0%—Wpmadeasy Shortcode Factory22/8/201917/6/2026
The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion.
ModificadaCrítica (9.8)12%—Getshortcodes Shortcodes Ultimate22/8/201917/6/2026
The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
ModificadaMedia (6.1)0.91%—Wpmadeeasy Shortcode Factory21/8/201917/6/2026
The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.