Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.38% | — | I13websolution Wordpress Vertical Image Slider | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution WordPress vertical image slider plugin <= 1.2.16 versions. | |
| Modificada | Alta (7.2) | 0.93% | — | Webtoffee Import Export Wordpress Users | 18/7/2023 | 17/6/2026 | The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with shop… | |
| Analizada | Alta (8.8) | 0.30% | — | Vibethemes Wordpress Learning Management System | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions. | |
| Modificada | Media (6.5) | 0.22% | — | Disable Wordpress Update Notifications AND Auto-update Email Notifications Project Disable Wordpress Update Notifications AND Auto-update Email Notifications | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Prem Tiwari Disable WordPress Update Notifications and auto-update Email Notifications plugin <= 2.3.3 versions. | |
| Modificada | Media (6.5) | 0.22% | — | Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions. | |
| Modificada | Media (6.5) | 0.22% | — | Wpmobilepack Wordpress Mobile Pack | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPMobilePack.Com WordPress Mobile Pack – Mobile Plugin for Progressive Web Apps & Hybrid Mobile Apps plugin <= 3.4.1 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Video Contest Wordpress Project Video Contest Wordpress | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in GalleryPlugins Video Contest WordPress plugin <= 3.2 versions. | |
| Modificada | Crítica (9.8) | 46% | 💥 Exploit | Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin) | 29/6/2023 | 17/6/2026 | The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for… | |
| Modificada | Media (4.8) | 0.55% | — | Kanbanwp Kanban Boards FOR Wordpress | 27/6/2023 | 17/6/2026 | The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.26% | — | Pluginus Wolf - Wordpress Posts Bulk Editor AND Manager Professional | 22/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7 versions. | |
| Modificada | Media (6.1) | 0.39% | — | Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview | 20/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Iksweb Wordpress Ctapt | 15/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in IKSWEB WordPress Старт plugin <= 3.7 versions. | |
| Modificada | Media (5.5) | 0.38% | — | Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO | 9/6/2023 | 17/6/2026 | The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.9) | 1.7% | — | Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO | 9/6/2023 | 17/6/2026 | The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by default)… | |
| Modificada | Media (5.4) | 0.36% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcs_current_currency shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Modificada | Media (4.3) | 0.41% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to… | |
| Modificada | Media (4.3) | 0.43% | — | Pluginus Wordpress Currency Switcher | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the anonymous function for the wpcs_sd_delete action in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.3) | 0.43% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above,… | |
| Modificada | Media (6.1) | 0.43% | — | I13websolution Wordpress Vertical Image Slider | 9/6/2023 | 17/6/2026 | The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_term’ parameter in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Valvepress Wordpress Automatic Plugin | 7/6/2023 | 17/6/2026 | The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to arbitrarily update the settings of a… | |
| Modificada | Alta (7.5) | 0.75% | — | Angrybyte Wordpress Exit BOX Lite | 5/6/2023 | 16/6/2026 | A vulnerability, which was classified as problematic, has been found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this issue is some unknown functionality of the file wordpress-exit-box-lite.php. The manipulation leads to information disclosure. The attack may be launched remotely. Upgrading to version… | |
| Modificada | Alta (8.8) | 0.43% | — | Angrybte Wordpress Exit BOX Lite | 5/6/2023 | 16/6/2026 | A vulnerability classified as problematic was found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this vulnerability is the function exitboxadmin of the file wordpress-exit-box-lite.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. Upgrading to version 1.10… | |
| Modificada | Media (5.4) | 0.43% | — | Accesspressthemes Frontend Post Wordpress Plugin | 5/6/2023 | 17/6/2026 | The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to an arbitrary domain. | |
| Modificada | Alta (8.8) | 0.43% | — | Wordpress Blogger Importer | 4/6/2023 | 16/6/2026 | A vulnerability was found in Blogger Importer Plugin up to 0.5 on WordPress. It has been classified as problematic. Affected is the function start/restart of the file blogger-importer.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. Upgrading to version 0.6 is… | |
| Modificada | Alta (8.8) | 0.26% | — | Wordpress Performance LAB | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress Performance Team Performance Lab plugin <= 2.2.0 versions. |