Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.71% | — | Paymattic Simple Payment Donations & Subscriptions | 5/9/2022 | 17/6/2026 | The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks against admins | |
| Modificada | Media (6.5) | 0.53% | — | Seamless Donations Project Seamless Donations | 20/6/2022 | 17/6/2026 | The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (5.4) | 0.57% | — | Donations Project Donations | 13/5/2022 | 17/6/2026 | Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPress. | |
| Modificada | Crítica (9.8) | 1.7% | — | Donations Project Donations | 25/4/2022 | 17/6/2026 | The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection | |
| Modificada | Media (6.5) | 0.54% | — | Wpplugin Accept Donations With Paypal | 24/1/2022 | 17/6/2026 | The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog | |
| Modificada | Media (4.8) | 0.62% | — | Wpplugin Accept Donations With Paypal | 17/11/2021 | 17/6/2026 | The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (4.3) | 0.47% | — | Wpplugin Accept Donations With Paypal | 1/11/2021 | 17/6/2026 | The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins… | |
| Modificada | Media (4.3) | 0.50% | — | Wpplugin Accept Donations With Paypal | 1/11/2021 | 17/6/2026 | The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not… | |
| Modificada | Media (6.1) | 1.3% | — | Donations Project Donations | 29/8/2019 | 17/6/2026 | The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. | |
| Modificada | Crítica (9.8) | 26% | 💥 Exploit | Calmar-webmedia Total Donations | 27/1/2019 | 17/6/2026 | Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the… |