Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 1.2% | — | Social LoginAI | 23/11/2024 | 17/6/2026 | The Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.9.0. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such… | |
| Analizada | Alta (8.1) | 0.52% | — | Heateor Social Login | 6/11/2024 | 17/6/2026 | The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user… | |
| Analizada | Alta (8.1) | 0.54% | — | Wpwebelite Woocommerce Social Login | 5/11/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on… | |
| Aplazada | Crítica (9.8) | 0.78% | — | Wpmet WP Social Login AND Register Social CounterAI | 26/10/2024 | 17/6/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any… | |
| Aplazada | Crítica (9.8) | 0.66% | — | Nextend Social Login PROAI | 16/10/2024 | 17/6/2026 | The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on… | |
| Aplazada | Crítica (9.8) | 0.85% | — | Wechat Social LoginAI | 1/10/2024 | 17/6/2026 | The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Aplazada | Crítica (9.8) | 1.7% | 💥 PoC | Wechat Social LoginAI | 1/10/2024 | 17/6/2026 | The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such… | |
| Analizada | Crítica (9.8) | 0.61% | — | Wpwebelite Woocommerce Social Login | 12/8/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for unauthenticated attackers to log in as any… | |
| Analizada | Alta (7.3) | 0.36% | — | Wpwebelite Woocommerce Social Login | 20/7/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This makes it possible for unauthenticated attackers to brute force the one-time password for… | |
| Analizada | Crítica (9.8) | 0.52% | — | Wpwebelite Woocommerce Social Login | 20/7/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to change the default role to Administrator… | |
| Analizada | Alta (7.3) | 0.40% | — | Wpwebelite Woocommerce Social Login | 20/7/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, excluding an… | |
| Modificada | Alta (7.5) | 0.31% | — | Wpwebelite Woocommerce Social Login | 9/7/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects WooCommerce Social Login: from n/a through <= 2.6.3. | |
| Modificada | Crítica (9.8) | 0.70% | — | Wpwebelite Woocommerce Social Login | 15/6/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is… | |
| Modificada | Media (5.3) | 0.31% | — | Wpwebelite Woocommerce Social Login | 15/6/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification. | |
| Modificada | Media (6.1) | 0.27% | — | Heateor Social Login | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login allows Cross-Site Scripting (XSS).This issue affects Heateor Social Login: from n/a through 1.1.32. | |
| Modificada | Media (5.4) | 0.26% | — | Heateor Social Login | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login allows Stored XSS.This issue affects Heateor Social Login: from n/a through 1.1.32. | |
| Aplazada | Crítica (9.8) | 0.57% | — | Social Login Lite FOR WoocommerceAI | 4/6/2024 | 17/6/2026 | The Social Login Lite For WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.6.0. This is due to insufficient verification on the user being supplied during the social login through the plugin. This makes it possible for unauthenticated attackers to log in as… | |
| Aplazada | Alta (8) | 0.48% | — | Miniorange Wordpress Social Login AND RegisterAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Privilege Escalation.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.6. | |
| Analizada | Media (5.4) | 0.34% | — | Heateor Social Login | 8/5/2024 | 17/6/2026 | Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. | |
| Modificada | Media (5.3) | 0.44% | — | Wpmet WP Social Login AND Register Social Counter | 13/3/2024 | 17/6/2026 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp_social/v1/ REST API endpoint in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to enable and disable… | |
| Modificada | Media (5.4) | 0.37% | — | Nextendweb Nextend Social Login | 2/3/2024 | 17/6/2026 | The Nextend Social Login and Register plugin for WordPress is vulnerable to a self-based Reflected Cross-Site Scripting via the ‘error_description’ parameter in all versions up to, and including, 3.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers,… | |
| Modificada | Media (5.4) | 0.32% | — | Heateor Social Login | 10/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Heateor Heateor Social Login WordPress allows Stored XSS.This issue affects Heateor Social Login WordPress: from n/a through 1.1.30. | |
| Modificada | Media (6.5) | 0.56% | — | Wpmet WP Social Login AND Register Social Counter | 19/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Counter.This issue affects Wp Social Login and Register Social Counter: from n/a through 1.9.0. | |
| Modificada | Crítica (9.8) | 0.95% | — | Knowband ONE Page Checkout, Social Login & Mailchimp | 5/10/2023 | 17/6/2026 | SQL injection vulnerability in KnowBand Module One Page Checkout, Social Login & Mailchimp (supercheckout) v.8.0.3 and before allows a remote attacker to execute arbitrary code via a crafted request to the updateCheckoutBehaviour function in the supercheckout.php component. | |
| Modificada | Media (6.4) | 0.42% | — | Wordpress Social Login Project Wordpress Social Login | 6/9/2023 | 17/6/2026 | The WordPress Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wordpress_social_login_meta' shortcode in versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… |