Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1062 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.27%—Wordpress Health Check & Troubleshooting25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions.
ModificadaAlta (8.8)0.27%—Viadat Store Locator FOR Wordpress With Google Maps24/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Viadat Creations Store Locator for WordPress with Google Maps – LotsOfLocales plugin <= 3.98.7 versions.
ModificadaAlta (8.8)0.26%—Hmplugin Wordpress Books Gallery23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin WordPress Books Gallery plugin <= 4.4.8 versions.
ModificadaAlta (8.8)0.26%—Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin)23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
ModificadaMedia (6.1)80%💥 ExploitWordpress17/5/202317/6/2026
WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload…
ModificadaMedia (4.8)0.37%—Kanbanwp Kanban Boards FOR Wordpress9/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kanban for WordPress Kanban Boards for WordPress plugin <= 2.5.20 versions.
ModificadaMedia (4.8)0.37%—Blueglass Jobs FOR Wordpress3/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.10.2 versions.
ModificadaMedia (5.4)0.36%—Wpdownloadmanager Gutenberg Blocks FOR Wordpress Download Manager3/5/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8 versions.
ModificadaMedia (4.8)0.37%—Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin)25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
ModificadaMedia (4.8)0.37%—Wordpress Custom Settings Project Wordpress Custom Settings23/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Davinder Singh Custom Settings plugin <= 1.0 versions.
ModificadaMedia (5.4)0.39%—Blueglass Jobs FOR Wordpress23/4/202317/6/2026
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.11.2 versions.
ModificadaMedia (4.8)0.44%—Wordpress Amazon S3 Project Wordpress Amazon S310/4/202317/6/2026
The WordPress Amazon S3 Plugin WordPress plugin before 1.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.38%—Cimatti Wordpress Contact Forms7/4/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.
ModificadaMedia (6.1)0.38%—Cimatti Wordpress Contact Forms7/4/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.
ModificadaMedia (5.4)0.37%—Followmedarling Spotify-play-button-for-wordpress5/4/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Jonk @ Follow me Darling Sp*tify Play Button for WordPress plugin <= 2.05 versions.
ModificadaMedia (4.8)0.35%—Followmedarling Spotify-play-button-for-wordpress4/4/202317/6/2026
The Sp*tify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.07 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and…
ModificadaAlta (8.8)0.22%—Wordpress Ping Optimizer Project Wordpress Ping Optimizer27/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Pankaj Jha WordPress Ping Optimizer plugin <= 2.35.1.2.3 versions.
ModificadaMedia (5.4)0.44%—Pluginus Wordpress Meta Data AND Taxonomies Filter22/3/202317/6/2026
The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripting vulnerability in the 'tax_name' parameter of the mdf_get_tax_options_in_widget action, which can only be triggered by an authenticated user.
ModificadaMedia (5.3)0.55%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart16/3/202317/6/2026
The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). This makes it…
ModificadaMedia (6.1)0.56%—Wordpress Debug BAR11/3/202316/6/2026
A vulnerability was found in dd32 Debug Bar Plugin up to 0.8 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function render of the file panels/class-debug-bar-queries.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version…
ModificadaMedia (4.3)0.46%—Xibodevelopment Backupwordpress7/3/202317/6/2026
The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions…
ModificadaMedia (5.4)0.47%—Synved Wordpress Shortcodes6/3/202317/6/2026
The WordPress Shortcodes WordPress plugin through 1.6.36 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.65%—Passwordprotectwp Password Protect Wordpress6/2/202317/6/2026
The PPWP WordPress plugin before 1.8.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
ModificadaMedia (6.1)1.2%💥 ExploitWpswings PDF Generator FOR Wordpress6/2/202317/6/2026
The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin
ModificadaAlta (7.5)0.80%—Getaawp Amazon Affiliate Wordpress Plugin30/1/202317/6/2026
The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.