Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.39% | — | Wpexperts Post SmtpAI | 18/3/2026 | 17/6/2026 | The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘event_type’ parameter in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Media (5.3) | 0.34% | — | Wpexperts Post SmtpAI | 18/3/2026 | 17/6/2026 | The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and including, 3.8.0. This is due to the function being hooked to `admin_init` without any `current_user_can()` check or… | |
| Aplazada | Alta (8.6) | 0.27% | — | Wpexperts NEW User ApproveAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through <= 3.2.0. | |
| Aplazada | Media (6.5) | 0.35% | — | Greg Winiarski WpadvertsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Greg Winiarski WPAdverts wpadverts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPAdverts: from n/a through <= 2.3.0. | |
| Aplazada | Alta (7.3) | 0.36% | — | Wpexperts NEW User ApproveAI | 28/1/2026 | 17/6/2026 | The New User Approve plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on multiple REST API endpoints in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to approve or deny user accounts, retrieve… | |
| Aplazada | Alta (8.5) | 0.29% | — | Saad Iqbal AppexpertsAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal AppExperts appexperts allows SQL Injection.This issue affects AppExperts: from n/a through <= 1.4.5. | |
| Aplazada | Media (5.3) | 0.33% | — | Wpexperts Protect WP AdminAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP-EXPERTS.IN Protect WP Admin protect-wp-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Protect WP Admin: from n/a through <= 4.1. | |
| Aplazada | Media (5.3) | 0.30% | — | Wpexperts Post SmtpAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= 3.6.1. | |
| Aplazada | Alta (7.1) | 0.12% | — | Wpexperts NEW User ApproveAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal New User Approve new-user-approve allows Cross Site Request Forgery.This issue affects New User Approve: from n/a through <= 3.2.3. | |
| Aplazada | Media (5.4) | 0.28% | — | Wpexperts Post SmtpAI | 3/12/2025 | 17/6/2026 | The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin not properly verifying that a user is authorized to update OAuth tokens on the 'handle_gmail_oauth_redirect' function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.29% | — | Wpexperts NEW User ApproveAI | 19/11/2025 | 17/6/2026 | The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and including, 3.0.9 due to insufficient API key validation using loose equality comparison. This makes it possible for unauthenticated attackers to retrieve personally identifiable information (PII),… | |
| Aplazada | Media (5.3) | 0.34% | — | Wpexperts ALL IN ONE LoginAI | 6/11/2025 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Saad Iqbal All In One Login change-wp-admin-login allows Identity Spoofing.This issue affects All In One Login: from n/a through <= 2.0.8. | |
| Aplazada | Crítica (9.8) | 61% | 💥 Exploit | Wpexperts Post SmtpAI | 1/11/2025 | 17/6/2026 | The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the __construct function in all versions up to, and including, 3.6.0. This makes it possible for unauthenticated attackers to read… | |
| Aplazada | Baja (3.7) | 0.31% | — | Wpexperts Password ProtectedAI | 25/10/2025 | 17/6/2026 | The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and similar headers) to determine user IP addresses in the… | |
| Aplazada | Media (5.8) | 0.30% | — | Saad Iqbal AppexpertsAI | 22/10/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal AppExperts appexperts allows Retrieve Embedded Sensitive Data.This issue affects AppExperts: from n/a through <= 1.4.5. | |
| Aplazada | Media (6.5) | 0.27% | — | Wpfactory AdvertsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Adverts adverts-click-tracker allows DOM-Based XSS.This issue affects Adverts: from n/a through <= 1.4. | |
| Aplazada | Media (5.9) | 0.30% | — | Wp-experts.in Sales Count Manager FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-EXPERTS.IN Sales Count Manager for WooCommerce wc-sales-count-manager allows Stored XSS.This issue affects Sales Count Manager for WooCommerce: from n/a through <= 2.6. | |
| Aplazada | Alta (7.6) | 0.37% | 💥 PoC | Wpexperts License Manager FOR WoocommerceAI | 5/9/2025 | 5/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Blind SQL Injection.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.12. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpexperts Post SmtpAI | 3/9/2025 | 17/6/2026 | The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_post_smtp_pro_option_callback' function in all… | |
| Aplazada | Alta (8.8) | 0.60% | 💥 PoC | Wpexperts Post SmtpAI | 7/8/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authentication Bypass.This issue affects Post SMTP: from n/a through <= 3.2.0. | |
| Aplazada | Media (6.5) | 0.18% | — | WpadvertsAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows DOM-Based XSS.This issue affects WPAdverts: from n/a through <= 2.2.5. | |
| Aplazada | Alta (8.1) | 0.58% | — | John Russell National Weather Service AlertsAI | 27/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Russell National Weather Service Alerts national-weather-service-alerts allows PHP Local File Inclusion.This issue affects National Weather Service Alerts: from n/a through <= 1.3.5. | |
| Aplazada | Media (6.5) | 0.19% | — | WpadvertsAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows DOM-Based XSS.This issue affects WPAdverts: from n/a through <= 2.2.4. | |
| Aplazada | Alta (8.5) | 0.30% | — | Wpexperts WC Partial ShipmentAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpExperts Hub Woocommerce Partial Shipment wc-partial-shipment allows SQL Injection.This issue affects Woocommerce Partial Shipment: from n/a through <= 3.2. | |
| Aplazada | Alta (8.2) | 0.39% | — | Chimpstudio Jobhunt JOB AlertsAI | 23/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Chimpstudio JobHunt Job Alerts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobHunt Job Alerts: from n/a through 3.6. |