Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.35% | — | Same BUT Different Related Posts BY TaxonomyAI | 7/1/2025 | 17/6/2026 | The Same but Different – Related Posts by Taxonomy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.16. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (5.3) | 0.36% | — | Pickplugins Related PostsAI | 5/12/2024 | 17/6/2026 | The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_related_post_ajax_get_post_ids AJAX action. This makes it possible for… | |
| Analizada | Crítica (9.8) | 45% | — | Yarpp YET Another Related Posts Plugin | 1/11/2024 | 17/6/2026 | Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10. | |
| Analizada | Media (5.9) | 0.45% | — | Data443 Inline Related Posts | 29/7/2024 | 17/6/2026 | The Inline Related Posts WordPress plugin before 3.8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.38% | — | Data443 Inline Related Posts | 12/7/2024 | 17/6/2026 | The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (4.8) | 0.26% | — | Yarpp YET Another Related Posts Plugin | 19/6/2024 | 17/6/2026 | The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Analizada | Media (6.5) | 0.84% | — | Yarpp YET Another Related Posts Plugin | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n/a through 5.30.4. | |
| Aplazada | Alta (7.1) | 0.25% | — | Microkid Related Posts FOR WordpressAI | 17/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Microkid Related Posts for WordPress allows Cross-Site Scripting (XSS).This issue affects Related Posts for WordPress: from n/a through 4.0.3. | |
| Aplazada | Media (4.3) | 0.20% | — | Data443 Inline Related PostsAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Data443 Inline Related Posts.This issue affects Inline Related Posts: from n/a through 3.3.1. | |
| Analizada | Media (4.3) | 0.45% | — | Data443 Inline Related Posts | 11/4/2024 | 17/6/2026 | The Inline Related Posts WordPress plugin before 3.6.0 is missing authorization in an AJAX action to ensure that users are allowed to see the content of the posts displayed, allowing any authenticated user, such as subscriber to retrieve the content of password protected posts | |
| Analizada | Media (4.8) | 0.42% | — | Data443 Inline Related Posts | 6/4/2024 | 17/6/2026 | The Inline Related Posts WordPress plugin before 3.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (5.4) | 0.28% | — | Never5 Related Posts | 13/3/2024 | 17/6/2026 | The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the handle_create_link() function. This makes it possible for unauthenticated attackers to add related posts to other… | |
| Modificada | Media (4) | 0.51% | — | Yarpp YET Another Related Posts Plugin | 29/2/2024 | 17/6/2026 | The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Analizada | Alta (8.8) | 0.94% | — | Yarpp YET Another Related Posts Plugin | 16/8/2023 | 17/6/2026 | The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks. | |
| Modificada | Media (5.4) | 0.51% | — | Yarpp YET Another Related Posts Plugin | 18/7/2023 | 17/6/2026 | The YARPP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'className' parameter in versions up to, and including, 5.30.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (5.4) | 0.71% | — | Yarpp YET Another Related Posts Plugin | 13/2/2023 | 17/6/2026 | The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.54% | — | Webberzone Contextual Related Posts | 6/2/2023 | 17/6/2026 | The Contextual Related Posts WordPress plugin before 3.3.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 1.2% | — | Never5 Related Posts | 14/10/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3. | |
| Modificada | Media (4.8) | 0.69% | — | Never5 Related Posts | 19/7/2021 | 17/6/2026 | The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Site Scripting issues. | |
| Modificada | Media (5.4) | 0.63% | — | Sovrn Wordpress Related Posts | 5/4/2021 | 17/6/2026 | The WordPress Related Posts plugin through 3.6.4 contains an authenticated (admin+) stored XSS vulnerability in the title field on the settings page. By exploiting that an attacker will be able to execute JavaScript code in the user's browser. | |
| Modificada | Media (5.4) | 0.63% | — | Never5 Related Posts | 5/4/2021 | 17/6/2026 | Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL. | |
| Modificada | Media (6.1) | 1.00% | — | Never5 Related Posts | 28/8/2019 | 17/6/2026 | The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Alta (7.5) | 2.0% | — | Ajaydsouza Contextual Related Posts | 2/6/2014 | 17/6/2026 | SQL injection vulnerability in the Contextual Related Posts plugin before 1.8.10.2 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.8) | 1.1% | — | Zemanta Related Posts | 2/6/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WordPress Related Posts plugin before 2.6.2 for WordPress allows remote attackers to hijack the authentication of users for requests that change settings via unspecified vectors. |