Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 662 respecto a la semana anterior
Críticas / altas1264▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.61% | — | Najeebmedia Wordpress Comments Fields | 8/8/2022 | 17/6/2026 | The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (6.1) | 0.68% | — | Sigmaplugin Advanced Wordpress Reset | 1/8/2022 | 17/6/2026 | The Advanced WordPress Reset WordPress plugin before 1.6 does not escape some generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting | |
| Modificada | Media (4.8) | 0.58% | — | Miniorange Wordpress Security | 27/6/2022 | 17/6/2026 | The WordPress Security Firewall, Malware Scanner, Secure Login and Backup plugin before 4.2.1 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for… | |
| Modificada | Media (4.8) | 0.67% | — | Miniorange Login Using Wordpress Users | 27/6/2022 | 17/6/2026 | The Login using WordPress Users ( WP as SAML IDP ) WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.2) | 1.3% | — | Soflyy Export ANY Wordpress Data TO Xml/csv | 13/6/2022 | 17/6/2026 | The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability. | |
| Modificada | Alta (8.8) | 0.41% | — | Disable Right Click FOR WP Wordpress Disable Right Click FOR WP | 20/5/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Aftab Muni's Disable Right Click For WP plugin <= 1.1.6 at WordPress. | |
| Analizada | Media (4.8) | 0.52% | — | Ibericode Mailchimp FOR Wordpress | 20/5/2022 | 17/6/2026 | Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Welaunch Wordpress Country Selector | 25/4/2022 | 17/6/2026 | Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specified payload as a part of the HTTP request | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | English Wordpress Admin Project English Wordpress Admin | 25/4/2022 | 17/6/2026 | The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue | |
| Modificada | Media (6.5) | 0.73% | — | Wordpress | 18/4/2022 | 16/6/2026 | A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission. | |
| Modificada | Alta (8.8) | 0.61% | — | Translate Wordpress With Gtranslate | 28/3/2022 | 17/6/2026 | The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin… | |
| Modificada | Alta (8.8) | 2.8% | — | Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO | 28/3/2022 | 17/6/2026 | The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code… | |
| Modificada | Media (5.5) | 0.70% | — | Patreon Wordpress | 14/3/2022 | 17/6/2026 | The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (6.5) | 0.53% | — | Devowl Wordpress Real Cookie Banner | 7/3/2022 | 17/6/2026 | The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack | |
| Modificada | Media (5.4) | 0.67% | — | Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO | 7/3/2022 | 17/6/2026 | The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.67% | — | Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO | 7/3/2022 | 17/6/2026 | The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks | |
| Modificada | Media (4.3) | 0.43% | — | Madewithfuel Customize Wordpress Emails AND Alerts | 28/2/2022 | 17/6/2026 | The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.). | |
| Modificada | Media (6.1) | 2.0% | 💥 Exploit | Feedwordpress Project Feedwordpress | 21/2/2022 | 17/6/2026 | The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter. | |
| Modificada | Media (4.7) | 0.75% | — | Translate Wordpress With Gtranslate | 7/2/2022 | 17/6/2026 | The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT… | |
| Modificada | Media (6.1) | 71% | 💥 Exploit | Codemiq Wordpress Email Template Designer | 4/2/2022 | 17/6/2026 | The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9.… | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | Welaunch Wordpress Gdpr&ccpa | 1/2/2022 | 17/6/2026 | The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this… | |
| Modificada | Crítica (9.6) | 2.1% | — | Welaunch Wordpress Gdpr&ccpa | 1/2/2022 | 17/6/2026 | The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this… | |
| Modificada | Alta (8.8) | 3.8% | — | WordpressDebian LinuxFedoraproject Fedora | 6/1/2022 | 17/6/2026 | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also… | |
| Modificada | Alta (7.2) | 3.7% | — | WordpressDebian LinuxFedoraproject Fedora | 6/1/2022 | 17/6/2026 | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected… | |
| Modificada | Media (5.4) | 65% | — | WordpressDebian Linux | 6/1/2022 | 17/6/2026 | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress… |