Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 662 respecto a la semana anterior
Críticas / altas1264▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1062 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.61%—Najeebmedia Wordpress Comments Fields8/8/202217/6/2026
The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-privileged users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (6.1)0.68%—Sigmaplugin Advanced Wordpress Reset1/8/202217/6/2026
The Advanced WordPress Reset WordPress plugin before 1.6 does not escape some generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting
ModificadaMedia (4.8)0.58%—Miniorange Wordpress Security27/6/202217/6/2026
The WordPress Security Firewall, Malware Scanner, Secure Login and Backup plugin before 4.2.1 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for…
ModificadaMedia (4.8)0.67%—Miniorange Login Using Wordpress Users27/6/202217/6/2026
The Login using WordPress Users ( WP as SAML IDP ) WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (7.2)1.3%—Soflyy Export ANY Wordpress Data TO Xml/csv13/6/202217/6/2026
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.
ModificadaAlta (8.8)0.41%—Disable Right Click FOR WP Wordpress Disable Right Click FOR WP20/5/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Aftab Muni's Disable Right Click For WP plugin <= 1.1.6 at WordPress.
AnalizadaMedia (4.8)0.52%—Ibericode Mailchimp FOR Wordpress20/5/202217/6/2026
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <= 4.8.6 at WordPress.
ModificadaMedia (6.1)1.4%💥 ExploitWelaunch Wordpress Country Selector25/4/202217/6/2026
Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specified payload as a part of the HTTP request
ModificadaMedia (6.1)1.9%💥 ExploitEnglish Wordpress Admin Project English Wordpress Admin25/4/202217/6/2026
The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue
ModificadaMedia (6.5)0.73%—Wordpress18/4/202216/6/2026
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
ModificadaAlta (8.8)0.61%—Translate Wordpress With Gtranslate28/3/202217/6/2026
The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin…
ModificadaAlta (8.8)2.8%—Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO28/3/202217/6/2026
The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code…
ModificadaMedia (5.5)0.70%—Patreon Wordpress14/3/202217/6/2026
The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (6.5)0.53%—Devowl Wordpress Real Cookie Banner7/3/202217/6/2026
The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack
ModificadaMedia (5.4)0.67%—Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO7/3/202217/6/2026
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
ModificadaMedia (5.4)0.67%—Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO7/3/202217/6/2026
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks
ModificadaMedia (4.3)0.43%—Madewithfuel Customize Wordpress Emails AND Alerts28/2/202217/6/2026
The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.).
ModificadaMedia (6.1)2.0%💥 ExploitFeedwordpress Project Feedwordpress21/2/202217/6/2026
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
ModificadaMedia (4.7)0.75%—Translate Wordpress With Gtranslate7/2/202217/6/2026
The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT…
ModificadaMedia (6.1)71%💥 ExploitCodemiq Wordpress Email Template Designer4/2/202217/6/2026
The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9.…
ModificadaMedia (6.1)2.3%💥 ExploitWelaunch Wordpress Gdpr&ccpa1/2/202217/6/2026
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this…
ModificadaCrítica (9.6)2.1%—Welaunch Wordpress Gdpr&ccpa1/2/202217/6/2026
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this…
ModificadaAlta (8.8)3.8%—WordpressDebian LinuxFedoraproject Fedora6/1/202217/6/2026
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also…
ModificadaAlta (7.2)3.7%—WordpressDebian LinuxFedoraproject Fedora6/1/202217/6/2026
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected…
ModificadaMedia (5.4)65%—WordpressDebian Linux6/1/202217/6/2026
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress…
Orbitaley — Vulnerabilidades