Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

200 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.47%—Blocks FOR ACF FieldsAI9/7/20269/7/2026
The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. The permission_callback only verifies the generic…
AplazadaAlta (7.2)0.54%—Advanced Product FieldsAI15/6/202617/6/2026
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
AplazadaMedia (6.9)0.13%—Wordpress More FieldsAI15/6/202617/6/2026
WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes on the Write/Edit…
AplazadaMedia (5.3)0.52%—Advancedcustomfields Advanced Custom FieldsAI31/5/202622/7/2026
The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the post_title and…
AplazadaCrítica (9.8)0.87%—Acfextended Advanced Custom Fields ExtendedAI28/5/202621/7/2026
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with…
AplazadaMedia (6.5)0.22%—Advancedcustomfields Font Awesome FieldAI27/5/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced Custom Fields: Font Awesome Field allows Stored XSS. This issue affects Advanced Custom Fields: Font Awesome Field: from n/a through 5.0.2.
AnalizadaCrítica (9.3)0.38%—Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+427/5/202617/6/2026
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
AplazadaMedia (4.3)0.18%—Search Simple FieldsAI27/5/202617/6/2026
The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the search_simple_fields_options() function in functions_admin.php. This makes it possible for unauthenticated attackers to modify the…
AplazadaMedia (6.9)0.53%—Simple FieldsAI17/5/202617/6/2026
Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null bytes into the wp_abspath parameter on PHP versions before 5.3.4. Attackers can supply malicious wp_abspath values to simple_fields.php to…
AplazadaMedia (6.4)0.35%—Advanced Custom Fields Font AwesomeAI15/5/202617/6/2026
The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due to insufficient input validation of JSON field values and unsafe client-side HTML construction in the update_preview() JavaScript function. This makes it…
AplazadaMedia (6.5)0.38%—Acfextended Advanced Custom Fields ExtendedAI12/5/202630/9/2026
The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for…
AplazadaAlta (8.7)0.60%—Conditional Fields FOR Contact Form 7AI4/5/202617/6/2026
Conditional Fields for Contact Form 7 WordPress plugin through version 2.7.2 contains an uncontrolled resource consumption vulnerability in the Wpcf7cfMailParser class where the hide_hidden_mail_fields_regex_callback() method reads an iteration count directly from user-supplied POST parameters without validation or…
AplazadaCrítica (9.8)0.87%—User Registration Advanced FieldsAI2/5/202617/6/2026
The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_AJAX::method_upload' function in all versions up to, and including, 1.6.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected…
AplazadaAlta (8.7)0.74%—Buddypress Xprofile Custom Fields TypeAI29/4/202617/6/2026
BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attackers can modify the field_hiddenfile and field_deleteimg parameters during profile editing to unlink files from the…
AplazadaMedia (5.3)0.86%—Advancedcustomfields Advanced Custom FieldsAI15/4/202617/6/2026
The Advanced Custom Fields (ACF) plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Post/Page Disclosure in versions up to and including 6.7.0. This is due to AJAX field query endpoints accepting user-supplied filter parameters that override field-configured restrictions without proper…
AnalizadaMedia (6.1)0.25%—Joaopaulocdev Calculation Fields26/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Calculation Fields allows Cross-Site Scripting (XSS).This issue affects Calculation Fields: from 0.0.0 before 1.0.4.
AplazadaMedia (4.3)0.34%—Smart Custom FieldsAI23/3/202617/6/2026
The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 5.0.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to read private…
AplazadaMedia (4.3)0.19%—ADD Custom Fields TO MediaAI19/3/202617/6/2026
The Add Custom Fields to Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.3. This is due to missing nonce validation on the field deletion functionality in the admin display template. The plugin properly validates a nonce for the 'add field' operation…
AnalizadaCrítica (9.1)0.30%—Teclib-edition Fields16/3/202617/6/2026
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.
AplazadaMedia (6.4)0.33%—Calculated Fields FormAI13/3/202617/6/2026
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in all versions up to, and including, 5.4.5.0. This is due to insufficient capability checks on the form settings save handler and insufficient input sanitization of the `fcontent` field in `fhtml` field…
AplazadaMedia (5.3)0.29%—Wombat Advanced Product Fields FOR WoocommerceAI13/3/202617/6/2026
Missing Authorization vulnerability in Wombat Plugins Advanced Product Fields (Product Addons) for WooCommerce advanced-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Product Fields (Product Addons) for WooCommerce: from n/a through <=…
AplazadaAlta (7.7)0.47%—Vanquish User Extra FieldsAI20/2/202617/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Traversal.This issue affects User Extra Fields: from n/a through <= 17.0.
AplazadaAlta (8.6)0.54%—Vanquish User Extra FieldsAI20/2/202617/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Traversal.This issue affects User Extra Fields: from n/a through <= 17.0.
AplazadaAlta (7.1)0.18%—Vanquish User Extra FieldsAI20/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Reflected XSS.This issue affects User Extra Fields: from n/a through <= 16.8.
AplazadaMedia (6.5)0.26%—Codepeople Calculated Fields FormAI19/2/202617/6/2026
Missing Authorization vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Calculated Fields Form: from n/a through <= 5.4.4.1.