Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.33% | — | Jonathonkemp Wordpress Users | 29/1/2024 | 17/6/2026 | The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | |
| Modificada | Media (6.1) | 27% | 💥 Exploit | Abhinavsingh Wordpress Toolbar | 29/1/2024 | 17/6/2026 | The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action. | |
| Modificada | Media (4.8) | 0.30% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 27/1/2024 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic redirect URL setting in all versions up to and including 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Modificada | Alta (7.2) | 1.2% | — | Soflyy Export ANY Wordpress Data TO Xml/csv | 22/1/2024 | 17/6/2026 | The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip file into a publicly accessible directory without sufficiently validating the extracted file type. This may allows high privilege users such as administrator to upload an executable file type… | |
| Modificada | Crítica (9.8) | 1.0% | — | Dmparekh Wordpress Database Administrator | 16/1/2024 | 17/6/2026 | The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Modificada | Alta (7.2) | 1.4% | — | Webtoffee Import Export Wordpress Users | 11/1/2024 | 17/6/2026 | The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'upload_import_file' function in versions up to, and including, 2.4.8. This makes it possible for authenticated attackers with shop manager-level capabilities or above,… | |
| Modificada | Media (4.8) | 0.34% | — | Hamidrezasepehr WP Custom Cursors | Wordpress Cursor Plugin | 8/1/2024 | 17/6/2026 | The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.2) | 0.54% | — | Geomywp GEO MY Wordpress | 31/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.0.2. | |
| Modificada | Media (5.4) | 0.32% | — | Automattic Wordpress.com Editing Toolkit | 29/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress.Com Editing Toolkit allows Stored XSS.This issue affects WordPress.Com Editing Toolkit: from n/a through 3.78784. | |
| Modificada | Alta (7.2) | 0.82% | — | Kanbanwp Kanban Boards FOR Wordpress | 29/12/2023 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Kanban for WordPress Kanban Boards for WordPress.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21. | |
| Modificada | Alta (8.8) | 0.55% | — | Soflyy Export ANY Wordpress Data TO Xml/csvSoflyy WP ALL Export | 18/12/2023 | 17/6/2026 | The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR… | |
| Modificada | Alta (8.8) | 0.55% | — | Soflyy Export ANY Wordpress Data TO Xml/csvSoflyy WP ALL Export | 18/12/2023 | 17/6/2026 | The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged in users perform unwanted actions leading to remote code execution. | |
| Modificada | Alta (7.2) | 1.2% | — | Soflyy Export ANY Wordpress Data TO Xml/csvSoflyy WP ALL Export | 18/12/2023 | 17/6/2026 | The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server | |
| Modificada | Alta (8.8) | 0.25% | — | Giftup Gift UP Gift Cards FOR Wordpress AND Woocommerce | 15/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Gift Up Gift Up Gift Cards for WordPress and WooCommerce.This issue affects Gift Up Gift Cards for WordPress and WooCommerce: from n/a through 2.21.3. | |
| Modificada | Crítica (9.8) | 1.1% | — | Bedevious Password Reset With Code FOR Wordpress Rest API | 7/12/2023 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15. | |
| Modificada | Media (4.8) | 0.39% | — | Slimndap Theater FOR Wordpress | 23/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Theater for WordPress plugin <= 0.18.3 versions. | |
| Modificada | Media (5.4) | 0.43% | — | Dwuser Easyrotator FOR Wordpress | 22/11/2023 | 17/6/2026 | The EasyRotator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyrotator' shortcode in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Alta (8.8) | 0.29% | — | Patreon Wordpress | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Patreon Patreon WordPress.This issue affects Patreon WordPress: from n/a through 1.8.6. | |
| Modificada | Alta (8.8) | 0.34% | — | Wordpress Tooltips | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tomas | Docs | FAQ | Premium Support WordPress Tooltips.This issue affects WordPress Tooltips: from n/a through 8.2.5. | |
| Modificada | Alta (8.8) | 0.27% | — | Cimatti Wordpress Contact Forms | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.6.0 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Freelancer-coder Wordpress Simple Html Sitemap | 8/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions. | |
| Modificada | Crítica (9.8) | 0.85% | — | Webtoffee Wordpress Comments Import AND Export | 7/11/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.1. | |
| Modificada | Media (5.4) | 0.58% | — | Giftup Gift UP Gift Cards FOR Wordpress AND Woocommerce | 7/11/2023 | 17/6/2026 | The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'giftup' shortcode in all versions up to, and including, 2.20.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Alta (7.2) | 0.73% | — | Highfivery Zero Spam FOR Wordpress | 3/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Highfivery LLC Zero Spam for WordPress allows SQL Injection.This issue affects Zero Spam for WordPress: from n/a through 5.4.4. | |
| Modificada | Media (4.3) | 0.49% | — | Userprivatefiles Wordpress File Sharing Plugin | 31/10/2023 | 17/6/2026 | The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced |