Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
293 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | Linksoftwarellc WP Terms PopupAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Link Software LLC WP Terms Popup wp-terms-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Terms Popup: from n/a through <= 2.10.0. | |
| Aplazada | Alta (7.2) | 0.48% | — | Wowoptin Next-gen Popup MakerAI | 21/3/2026 | 17/6/2026 | The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.29. This is due to the plugin exposing a publicly accessible REST API endpoint (optn/v1/integration-action) with a permission_callback of __return_true that passes… | |
| Aplazada | Media (5.3) | 0.48% | — | Instant Popup BuilderAI | 19/3/2026 | 17/6/2026 | The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all versions up to and including 1.1.7. This is due to the handle_email_verification_page() function constructing a shortcode string from user-supplied GET parameters (token, email) and passing it to… | |
| Aplazada | Media (5.3) | 0.29% | — | AYS Facebook Popup LikeboxAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Ays Pro Popup Like box ays-facebook-popup-likebox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Like box: from n/a through <= 3.7.7. | |
| Aplazada | Media (4.4) | 0.20% | — | Lotekmedia Popup FormAI | 7/3/2026 | 17/6/2026 | The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Alta (8.8) | 0.49% | — | WP Life Modal Popup BOXAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in A WP Life Modal Popup Box modal-popup-box allows Object Injection.This issue affects Modal Popup Box: from n/a through <= 1.6.1. | |
| Aplazada | Media (5.3) | 0.39% | — | Popup BuilderAI | 19/2/2026 | 17/6/2026 | The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.2. This is due to the plugin generating predictable unsubscribe tokens using deterministic data. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.20% | — | Popup BOXAI | 18/2/2026 | 17/6/2026 | The Popup Box – Easily Create WordPress Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortcode in all versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.38% | — | PrestashopAIAdvancedpopupcreatorAI | 13/2/2026 | 17/6/2026 | A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup controller. The parameter is passed unsanitized… | |
| Aplazada | Media (6.4) | 0.26% | — | Wdes Responsive PopupAI | 11/2/2026 | 17/6/2026 | The WDES Responsive Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdes-popup-title' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.4) | 0.30% | — | PopupkitAI | 10/2/2026 | 17/6/2026 | The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. This is due to the plugin not properly verifying that a user is authorized to access the /popup/logs REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Alta (8.2) | 0.44% | — | Popup BuilderAI | 5/2/2026 | 17/6/2026 | The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to generic SQL Injection via the multiple REST API endpoints in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Media (4.3) | 0.18% | — | Neliosoftware Nelio PopupsAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Nelio Software Nelio Popups nelio-popups allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nelio Popups: from n/a through <= 1.3.5. | |
| Aplazada | Media (4.3) | 0.19% | — | Popup BOXAI | 31/1/2026 | 17/6/2026 | The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1.1. This is due to a flawed nonce implementation in the 'publish_unpublish_popupbox' function that verifies a self-created nonce rather than one submitted in the request. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.23% | — | Damian Wp-popups-liteAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Damian WP Popups wp-popups-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Popups: from n/a through <= 2.2.0.5. | |
| Aplazada | Media (6.4) | 0.22% | — | Convertforce Popup BuilderAI | 10/1/2026 | 17/6/2026 | The ConvertForce Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gutenberg block's `entrance_animation` attribute in all versions up to, and including, 0.0.7. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.22% | — | WP Popup MagicAI | 9/1/2026 | 17/6/2026 | The WP Popup Magic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the [wppum_end] shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (4.3) | 0.23% | — | PopupkitAI | 6/1/2026 | 17/6/2026 | The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on the DELETE `/subscribers` REST API endpoint in all versions up to, and including, 2.2.0. This is due to the `permission_callback` only validating wp_rest nonce without checking user capabilities. This… | |
| Aplazada | Media (6.5) | 0.29% | — | Page Expire Popup RedirectionAI | 6/1/2026 | 17/6/2026 | The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' shortcode attribute in all versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Aplazada | Media (5.3) | 0.28% | — | Popup AND Slider Builder BY DepicterAI | 6/1/2026 | 17/6/2026 | The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'store' function of the RulesAjaxController class in all… | |
| Aplazada | Media (4.3) | 0.22% | — | Roxnor PopupkitAI | 30/12/2025 | 5/10/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roxnor PopupKit popup-builder-block allows Retrieve Embedded Sensitive Data.This issue affects PopupKit: from n/a through <= 2.1.5. | |
| Aplazada | Media (5.4) | 0.12% | — | AYS Popup BOXAI | 30/12/2025 | 5/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.This issue affects Popup box: from n/a through <= 6.0.7. | |
| Aplazada | Media (4.3) | 0.27% | — | Crocoblock JetpopupAI | 29/12/2025 | 1/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup jet-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetPopup: from n/a through <= 2.0.20.1. | |
| Aplazada | Media (5.3) | 0.25% | — | Claspo Popup BuildersAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Claspo Popup Builders Claspo – Popups, Spin the Wheel & Email Capture claspo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Claspo – Popups, Spin the Wheel & Email Capture: from n/a through <= 1.0.7. | |
| Aplazada | Media (5.3) | 0.23% | — | Brave-popup-builderAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Brave Brave brave-popup-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brave: from n/a through <= 0.8.3. |