Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1971 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.3)0.54%—Create Custom Forms FOR Wordpress With A Smart Form Plugin FOR Smart BusinessesAI26/4/202517/6/2026
The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.4. This is due to the software allowing users to execute an action that does not properly validate a value before running…
AplazadaMedia (5.3)0.40%—Prevent Direct Access Protect Wordpress FilesAI25/4/202517/6/2026
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'generate_unique_string' due to insufficient randomness of the generated file name. This makes it possible for unauthenticated attackers to…
AplazadaMedia (4.2)0.22%—Buddypress Force Password ChangeAI24/4/202517/6/2026
The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for…
AplazadaMedia (5.3)0.29%—Reales WP Real Estate Wordpress ThemeAI24/4/202517/6/2026
The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'reales_delete_file', 'reales_delete_file_plans', 'reales_add_to_favourites', and 'reales_remove_from_favourites' functions in all versions up to, and…
AplazadaAlta (7.5)0.53%—Wordpress Simple Shopping CartAI23/4/202517/6/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up to, and including, 5.1.2. This is due to a logic flaw involving the inconsistent use of parameters during the cart addition process. The plugin uses the parameter 'product_tmp_two' for computing a…
AplazadaAlta (8.2)0.40%—Wordpress Simple Shopping CartAI23/4/202517/6/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' parameter. This makes it possible for unauthenticated attackers to view potentially sensitive information and download a digital product without paying…
AplazadaAlta (7.1)0.15%—Amazon Showcase Wordpress WidgetAI17/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Aaron Forgue Amazon Showcase WordPress Plugin amazon-showcase-wordpress-widget allows Stored XSS.This issue affects Amazon Showcase WordPress Plugin: from n/a through <= 2.2.
AplazadaAlta (7.1)0.15%—Eslam Mahmoud Redirect Wordpress TO Welcome OR Landing PageAI17/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Eslam Mahmoud Redirect wordpress to welcome or landing page redirect-to-welcome-or-landing-page allows Stored XSS.This issue affects Redirect wordpress to welcome or landing page: from n/a through <= 2.0.
AplazadaAlta (7.1)0.31%—Exeideas International WP AutokeywordAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EXEIdeas International WP AutoKeyword wp-autokeyword allows Stored XSS.This issue affects WP AutoKeyword: from n/a through <= 1.0.
AplazadaAlta (7.1)0.29%—M ALI Saleem Wordpress Health AND Server Condition Integrated With Google Page SpeedAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M. Ali Saleem WordPress Health and Server Condition – Integrated with Google Page Speed wp-condition allows Reflected XSS.This issue affects WordPress Health and Server Condition – Integrated with Google Page Speed:…
AplazadaMedia (5.9)0.40%—Webtoffee Wordpress Backup AND MigrationAI17/4/202517/6/2026
Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Retrieve Embedded Sensitive Data.This issue affects WordPress Backup & Migration: from n/a through <= 1.5.3.
AplazadaAlta (7.1)0.29%—Autoglot Automatic Wordpress TranslationAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Autoglot Autoglot – Automatic WordPress Translation autoglot allows Reflected XSS.This issue affects Autoglot – Automatic WordPress Translation: from n/a through <= 2.4.7.
AplazadaMedia (6.5)0.38%—Wpseek Wordpress Dashboard TweeterAI17/4/202517/6/2026
Missing Authorization vulnerability in wpseek WordPress Dashboard Tweeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress Dashboard Tweeter: from n/a through 1.3.2.
AplazadaMedia (6.5)0.27%—Studio Hyperset THE Great Firewords OF ChinaAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studio Hyperset The Great Firewords of China sensitive-chinese-words-scanner allows Stored XSS.This issue affects The Great Firewords of China: from n/a through <= 1.2.
AplazadaMedia (5.3)0.36%—Wpexperts Password ProtectedAI17/4/202517/6/2026
The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.7 via the 'password_protected_cookie' function. This…
AplazadaMedia (5.4)0.51%—Miniorange Wordpress Rest API AuthenticationAI16/4/202517/6/2026
Missing Authorization vulnerability in miniOrange WordPress REST API Authentication wp-rest-api-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress REST API Authentication: from n/a through <= 3.6.3.
AplazadaCrítica (9.1)0.43%—Insert OR Embed Articulate Content Into WordpressAI10/4/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articulate Content into WordPress insert-or-embed-articulate-content-into-wordpress allows Upload a Web Shell to a Web Server.This issue affects Insert or Embed Articulate Content into WordPress: from n/a…
AplazadaAlta (7.1)0.42%—Ankit Singla Wordpress Spam BlockerAI9/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ankit Singla WordPress Spam Blocker cf7-manual-spam-blocker allows Stored XSS.This issue affects WordPress Spam Blocker: from n/a through <= 2.0.5.
AnalizadaMedia (6.3)0.16%—Felixker Wordpress/plugin Upgrade Time OUT Plugin9/4/202517/6/2026
The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
AnalizadaAlta (7.5)0.46%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word8/4/202517/6/2026
Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaAlta (7.8)0.82%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+28/4/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AplazadaMedia (5.3)0.82%💥 Exploit1clickmigration 1 Click Wordpress MigrationAI4/4/202517/6/2026
Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration 1-click-migration allows Retrieve Embedded Sensitive Data.This issue affects 1 Click WordPress Migration: from n/a through <= 2.5.7.
AnalizadaCrítica (9.8)1.1%—Netwrix Password Secure3/4/202517/6/2026
Netwrix Password Secure through 9.2 allows command injection.
ModificadaCrítica (9.8)1.6%—Netwrix Password Secure3/4/202517/6/2026
Netwrix Password Secure 9.2.0.32454 allows OS command injection.
AplazadaAlta (7.1)0.29%—E1tekoap42 Search Engine Keywords HighlighterAI3/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e1tekoap42 Search engine keywords highlighter keywords-highlight-tool allows Reflected XSS.This issue affects Search engine keywords highlighter: from n/a through <= 0.1.3.
Orbitaley — Vulnerabilidades