Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

567 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.9)0.51%—Ljapps WP Tripadvisor Review SliderAI5/8/202612/8/2026
The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (6.1)0.36%—WP Responsive Thumbnail SliderAI1/8/202612/8/2026
The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management() function, which echoes $_GET['id']…
AplazadaMedia (4.3)0.14%—Ljapps WP Google Review SliderAI27/7/202627/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
AplazadaAlta (7.6)0.38%—Ljapps WP Google Review SliderAI27/7/202627/7/2026
Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
AplazadaMedia (4.3)0.27%—Product Slider FOR WoocommerceAI23/7/202623/7/2026
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
AplazadaAlta (7.1)0.25%—Slider PROAI23/7/202623/7/2026
Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.
AplazadaMedia (4.9)0.48%—Ljapps WP Tripadvisor Review SliderAI16/7/202616/7/2026
The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, 14.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (5.4)0.23%—Ultimate Before After Image Slider AND GalleryAI14/7/202629/9/2026
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front end (the value is passed through do_shortcode, which echoes non-shortcode content verbatim), allowing users with administrator-level…
AplazadaMedia (4.3)0.41%—Nextendweb Smart Slider 3AI13/7/202614/7/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles and full content excerpts of private, draft,…
AplazadaMedia (6.4)0.33%💥 PoCLogoslider Logo SliderAI10/7/202610/7/2026
The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lgx_tooltip_position' parameter in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.5)1.0%—Jssor SliderAI8/7/20268/7/2026
The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.1.24 via the 'url' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
AplazadaAlta (7.1)0.25%—Themepunch Slider RevolutionAI2/7/20262/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS. This issue affects Slider Revolution: from 7.0.0 through 7.0.16.
AplazadaAlta (7.5)0.46%—WP Review Slider PROAI2/7/20262/7/2026
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action in versions up to, and including, 12.7.2. The parameter is read via $_POST['notinstring'] and passed through sanitize_text_field() — which strips HTML and whitespace but…
AplazadaMedia (6.1)0.37%—WP Google Places Review SliderAI1/7/20261/7/2026
The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, and including, 18.1. This is due to insufficient input sanitization and output escaping in admin/partials/googlecrawl_dfs.php, where the $_GET['place'] value is…
AplazadaAlta (7.1)0.25%—Quick Interest SliderAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.
AplazadaAlta (7.1)0.25%—Masterslider Master SliderAI25/6/20266/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider master-slider allows Reflected XSS.This issue affects Master Slider: from n/a through 3.11.3.
AplazadaAlta (7.5)0.43%—Shapedsmart Smart Post Show PROAIReal Testimonials PROAIProduct Slider FOR Woocommerce PROAI24/6/202625/6/2026
Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for…
AplazadaAlta (8.1)0.82%—WP Review Slider PROAI16/6/202617/6/2026
The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function,…
AplazadaAlta (8.8)0.46%—WP Review Slider PROAI16/6/202617/6/2026
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type casting, then concatenating each array…
AplazadaAlta (8.8)0.46%—WP Review Slider PROAI16/6/202617/6/2026
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslashes() on user-supplied JSON strings prior to json_decode(), which…
AplazadaAlta (7.1)0.25%—Social Slider FeedAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions.
AplazadaCrítica (9.1)0.82%—Metaslider Responsive SliderAI15/6/202617/6/2026
Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.
AplazadaMedia (6.3)0.25%—Ljapps WP Google Review SliderAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions.
AplazadaMedia (5.3)0.10%—Wordpress Lazy Content SliderAI15/6/202617/6/2026
WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_admin.php to modify…
AplazadaMedia (5.3)0.24%—Essentialplugin WP Logo Showcase Responsive Slider AND CarouselAI11/6/202623/7/2026
Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider and Carousel allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Logo Showcase Responsive Slider and Carousel: from n/a through 3.6.
Orbitaley — Vulnerabilidades