Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1447 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.8) | 0.23% | — | Theeventscalendar THE Events CalendarAI | 23/9/2026 | 23/9/2026 | The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators. | |
| Aplazada | Baja (2.7) | 0.23% | — | Modern Tribe THE Events CalendarAI | 23/9/2026 | 23/9/2026 | The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review. | |
| Aplazada | Media (5.3) | 0.25% | — | Theeventscalendar THE Events CalendarAI | 23/9/2026 | 23/9/2026 | The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published. | |
| Aplazada | Media (4.9) | 0.38% | — | Event Booking ManagerAI | 17/9/2026 | 18/9/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys. | |
| Aplazada | Baja (3.7) | 0.26% | — | Event Booking Manager FOR WoocommerceAI | 17/9/2026 | 18/9/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom… | |
| Aplazada | Media (5.3) | 0.16% | — | Themewinter EventinAI | 16/9/2026 | 16/9/2026 | The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or which order it belongs to, allowing unauthenticated visitors to mark unpaid orders… | |
| Aplazada | Baja (3.7) | 0.25% | — | Themewinter EventinAI | 16/9/2026 | 17/9/2026 | The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) payment method is enabled, relying on a nonce that is exposed to unauthenticated visitors and never checking that the caller owns the order, allowing unauthenticated attackers to reset any existing order… | |
| Aplazada | Baja (2.7) | 0.28% | — | Themewinter EventinAI | 16/9/2026 | 17/9/2026 | The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that carry capabilities beyond their own, including publishing content and uploading files, and, by… | |
| Aplazada | Media (5.3) | 0.30% | — | Themewinter EventinAI | 16/9/2026 | 17/9/2026 | The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's tickets afterwards, allowing unauthenticated users to replace a paid ticket with a free one and complete the order at no charge. | |
| Aplazada | Alta (7.5) | 0.70% | — | Themewinter EventinAI | 15/9/2026 | 15/9/2026 | The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap`… | |
| Aplazada | Media (6.4) | 0.25% | — | Themewinter EventinAI | 15/9/2026 | 16/9/2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, 4.1.23 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Alta (7.5) | 0.40% | — | Mdjm Event ManagementAIMobileeventsmanager Mobile Events ManagerAI | 13/9/2026 | 14/9/2026 | The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to… | |
| Aplazada | Media (6.4) | 0.24% | — | Booking FOR Appointments AND Events CalendarAI | 12/9/2026 | 14/9/2026 | The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of… | |
| Aplazada | Crítica (9.8) | 1.4% | — | Theeventscalendar THE Events CalendarAI | 12/9/2026 | 14/9/2026 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and… | |
| Aplazada | Crítica (9.8) | 1.5% | — | Theeventscalendar THE Events CalendarAI | 12/9/2026 | 14/9/2026 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse,… | |
| Aplazada | Alta (7.2) | 0.46% | — | Ameliabooking Booking FOR Appointments AND Events CalendarAI | 12/9/2026 | 14/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address… | |
| Aplazada | Media (5.3) | 0.30% | — | Booking FOR Appointments AND Events CalendarAI | 12/9/2026 | 14/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an… | |
| Aplazada | Media (6.5) | 0.22% | — | Myeventon EventonAI | 10/9/2026 | 10/9/2026 | Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions. | |
| Aplazada | Media (4.3) | 0.29% | — | Wedevs EventinAI | 9/9/2026 | 9/9/2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Media (5.4) | 0.18% | — | Themewinter EventinAI | 9/9/2026 | 9/9/2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.80% | — | Themewinter EventinAI | 9/9/2026 | 9/9/2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Alta (7.5) | 0.66% | — | Themewinter EventinAI | 9/9/2026 | 11/9/2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to… | |
| Aplazada | Media (5.3) | 0.24% | — | Themewinter EventinAI | 9/9/2026 | 9/9/2026 | The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The endpoint's create_item_permissions_check() function only verifies a wp_rest nonce (which is leaked to… | |
| Aplazada | Alta (7.5) | 0.47% | — | Eventbrite Event TicketsAI | 8/9/2026 | 9/9/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant… | |
| Aplazada | Media (6.5) | 0.33% | — | WpeventlyAI | 8/9/2026 | 8/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions. |