Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.43% | — | Ilghera JW Player FOR WordpressAI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from n/a through 2.3.3. | |
| Analizada | Media (6.1) | 71% | 💥 Exploit | Wordpress | 3/5/2024 | 17/6/2026 | WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in… | |
| Aplazada | Media (4.3) | 0.49% | — | Wordpress Backup AND MigrationAI | 2/5/2024 | 17/6/2026 | The WordPress Backup & Migration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wp_mgdp_populate_popup function in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with subscriber access or above, to invoke this… | |
| Aplazada | Baja (2.7) | 0.65% | — | Xibodevelopment BackupwordpressAI | 27/4/2024 | 17/6/2026 | The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to traverse directories outside of the context in which the… | |
| Aplazada | Media (5.9) | 0.34% | — | Broadstreet Xpress Wordpress AD WidgetAI | 26/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet XPRESS WordPress Ad Widget allows Stored XSS.This issue affects WordPress Ad Widget: from n/a through 2.20.0. | |
| Aplazada | Media (5.4) | 0.36% | — | Webtoffee Import Export Wordpress UsersAI | 24/4/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.3. | |
| Aplazada | Media (5.3) | 0.55% | — | Fredericgilles FG Joomla TO WordpressAI | 24/4/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Joomla to WordPress.This issue affects FG Joomla to WordPress: from n/a through 4.20.2. | |
| Aplazada | Media (5.9) | 0.34% | — | Extendwp Import Content IN Wordpress AND Woocommerce With ExcelAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendWP Import Content in WordPress & WooCommerce with Excel allows Reflected XSS.This issue affects Import Content in WordPress & WooCommerce with Excel: from n/a through 4.2. | |
| Modificada | Media (6.1) | 0.39% | — | Blueglass Jobs FOR Wordpress | 18/4/2024 | 17/6/2026 | The Jobs for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘job-search’ parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (7.1) | 0.25% | — | Microkid Related Posts FOR WordpressAI | 17/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Microkid Related Posts for WordPress allows Cross-Site Scripting (XSS).This issue affects Related Posts for WordPress: from n/a through 4.0.3. | |
| Aplazada | Media (4.3) | 0.20% | — | Anton Aleksandrov Wordpress Hosting Benchmark ToolAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Anton Aleksandrov WordPress Hosting Benchmark tool.This issue affects WordPress Hosting Benchmark tool: from n/a through 1.3.6. | |
| Aplazada | Media (5.4) | 0.21% | — | Geomywp GEO MY WordpressAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.1. | |
| Modificada | Media (6.1) | 0.40% | — | Blueglass Jobs FOR Wordpress | 15/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Jobs for WordPress allows Reflected XSS.This issue affects Jobs for WordPress: from n/a through 2.7.5. | |
| Aplazada | Media (4.3) | 0.23% | — | Webtoffee Wordpress Comments Import ExportAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.5. | |
| Aplazada | Alta (7.1) | 0.18% | — | Wordpress TooltipsAI | 11/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tooltip WordPress Tooltips allows Stored XSS.This issue affects WordPress Tooltips: from n/a through 9.5.3. | |
| Aplazada | Media (4.3) | 0.20% | — | Soflyy Import ANY XML OR CSV File TO WordpressAI | 10/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Import any XML or CSV File to WordPress.This issue affects Import any XML or CSV File to WordPress: from n/a through 3.7.3. | |
| Modificada | Alta (8.8) | 0.22% | — | Pluginus Bear - Woocommerce Bulk Editor AND Products Manager ProfessionalPluginus Wolf - Wordpress Posts Bulk Editor AND Products Manager Professional | 10/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional, realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.This issue affects WOLF – WordPress Posts Bulk Editor and Manager Professional: from n/a through… | |
| Aplazada | Media (6.5) | 0.55% | — | Wpcloudgallery Wordpress Gallery ExporterAI | 10/4/2024 | 17/6/2026 | Missing Authorization vulnerability in WPcloudgallery WordPress Gallery Exporter.This issue affects WordPress Gallery Exporter: from n/a through 1.3. | |
| Analizada | Media (4.3) | 0.22% | — | Wordpress Ping Optimizer Project Wordpress Ping Optimizer | 10/4/2024 | 17/6/2026 | The WordPress Ping Optimizer WordPress plugin through 2.35.1.3.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as clearing logs. | |
| Modificada | Media (5.4) | 0.36% | — | Iptanus Wordpress File Upload | 9/4/2024 | 17/6/2026 | The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.24.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.9) | 0.83% | — | Wordpress Infinite ScrollAI | 9/4/2024 | 17/6/2026 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server,… | |
| Aplazada | Alta (8.5) | 0.52% | — | Codeisawesome Aikit Wordpress AI Writing Assistant Using Gpt3AI | 9/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeIsAwesome AIKit aikit-wordpress-ai-writing-assistant-using-gpt3.This issue affects AIKit: from n/a through <= 4.14.1. | |
| Aplazada | Media (5.3) | 0.84% | — | WordpressAI | 5/4/2024 | 17/6/2026 | WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'. | |
| Analizada | Crítica (9.8) | 2.8% | 💥 PoC | Wordpress | 4/4/2024 | 17/6/2026 | WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected. | |
| Analizada | Alta (8.8) | 0.95% | — | Wordpress | 4/4/2024 | 17/6/2026 | WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for installation (in order to move the file into… |