Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.53% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 23/1/2023 | 17/6/2026 | The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege… | |
| Modificada | Crítica (9.8) | 1.0% | — | Codeboxr CBX Petition FOR Wordpress | 23/1/2023 | 17/6/2026 | The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Modificada | Media (5.4) | 0.53% | — | Devowl Wordpress Real Cookie Banner | 16/1/2023 | 17/6/2026 | The Real Cookie Banner WordPress plugin before 3.4.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. | |
| Modificada | Media (6.1) | 0.89% | 💥 Exploit | Mhsoftware Wordpress Events Calendar Plugin | 16/1/2023 | 17/6/2026 | The WordPress Events Calendar WordPress plugin before 1.4.5 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high-privilege ones like admin). | |
| Modificada | Media (5.4) | 0.47% | — | Ipanorama 360 Wordpress Virtual Tour Builder Project Ipanorama 360 Wordpress Virtual Tour Builder | 9/1/2023 | 17/6/2026 | The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.3) | 1.7% | 💥 PoC | Wordpress | 5/1/2023 | 17/6/2026 | WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security… | |
| Modificada | Media (4.8) | 0.47% | — | Wordpress Filter Gallery Project Wordpress Filter Gallery | 2/1/2023 | 17/6/2026 | The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg_gallery_filters ajax action before outputting them on the page, allowing a high privileged user such as an administrator to inject HTML or javascript to the plugin settings page, even when the… | |
| Modificada | Alta (7.5) | 1.4% | — | Transposh Wordpress Translation | 15/12/2022 | 17/6/2026 | The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient validation of settings on the 'tp_translation' AJAX action which makes it possible for unauthenticated attackers to… | |
| Modificada | Media (5.9) | 3.2% | 💥 Exploit | Wordpress | 14/12/2022 | 17/6/2026 | WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden. | |
| Modificada | Alta (7.5) | 0.92% | — | Wordpress Popular Posts Project Wordpress Popular Posts | 7/12/2022 | 17/6/2026 | External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted… | |
| Modificada | Media (5.3) | 1.5% | — | Wordpress | 5/12/2022 | 17/6/2026 | Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The developer also provides new patched releases for all versions since 3.7. | |
| Modificada | Media (6.1) | 0.98% | — | Wordpress | 5/12/2022 | 17/6/2026 | Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7. | |
| Modificada | Media (6.1) | 1.3% | — | Wordpress | 5/12/2022 | 17/6/2026 | Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7. | |
| Modificada | Alta (8.8) | 0.29% | — | Miniorange Wordpress Rest API Authentication | 18/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress. | |
| Modificada | Media (5.3) | 0.48% | — | Wpchill Customizable Wordpress Gallery Plugin - Modula Image Gallery | 18/11/2022 | 17/6/2026 | Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress. | |
| Modificada | Media (4.3) | 0.34% | — | Wordpress Ping Optimizer Project Wordpress Ping Optimizer | 19/9/2022 | 17/6/2026 | The WordPress Ping Optimizer WordPress plugin before 2.35.1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (5.3) | 3.7% | 💥 Exploit | Transposh Wordpress Translation | 6/9/2022 | 17/6/2026 | The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_history' AJAX action and insufficient restriction on the data returned in the… | |
| Modificada | Media (5.3) | 4.8% | 💥 Exploit | Transposh Wordpress Translation | 6/9/2022 | 17/6/2026 | The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for… | |
| Modificada | Alta (8.8) | 1.6% | — | Radiustheme Team - Wordpress Team Members Showcase | 22/8/2022 | 17/6/2026 | The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user | |
| Modificada | Alta (7.2) | 1.7% | — | Transposh Wordpress Translation | 22/8/2022 | 17/6/2026 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allow allowing high privilege users such as admin to perform RCE | |
| Modificada | Alta (7.2) | 1.4% | — | Transposh Wordpress Translation | 22/8/2022 | 17/6/2026 | The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby parameters before using them in a SQL statement, leading to a SQL injection | |
| Modificada | Media (6.5) | 1.0% | — | Transposh Wordpress Translation | 22/8/2022 | 17/6/2026 | The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_reset” under the Utilities tab (/wp-admin/admin.php?page=tp_utils), which can be used/executed as the lowest-privileged user. Basically all Utilities functionalities are vulnerable this way, which… | |
| Modificada | Media (5.4) | 0.34% | — | Transposh Wordpress Translation | 22/8/2022 | 17/6/2026 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. Given the lack of sanitisation in the tk0 parameter, this could lead to a Stored Cross-Site Scripting issue which will be… | |
| Modificada | Media (5.4) | 0.67% | — | Transposh Wordpress Translation | 22/8/2022 | 17/6/2026 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The minimum role needed to perform such attack depends on the plugin… | |
| Modificada | Media (6.1) | 1.6% | 💥 Exploit | Transposh Wordpress Translation | 22/8/2022 | 17/6/2026 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue |